Risky to adopt: this release has seen no updates or releases for nearly 10 years. It is licensed, documented, and backed by an organization, but the tiny repository and complete lack of recent maintenance make abandonment a serious concern.
40%
Total Score
50
67
50
The package has only two releases, both published on January 28, 2016, with no release in nearly 10 years. This strongly indicates an inactive release line.
There were zero commits and zero active maintainers in the last three months, consistent with no meaningful repository activity since January 2016. This is the main abandonment risk.
The repository name matches the package, reducing the risk of an unrelated repository, but the README does not mention the package name. That weakens the evidence that the repository documentation directly supports this registry package.
The repository has zero stars and one fork, with four watchers, indicating very limited adoption or visible community support. Popularity is supporting evidence, but this reinforces the maintenance concern.
The repository uses Composer, showing basic build or package tooling, but it has no security scanning tools. The missing scanning is a hygiene gap, though the absence of workflows limits the associated operational risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.