Its MIT declaration and tiny Composer-only artifact make its licensing and installation shape clear. The repository is unarchived but has no reported security policy or scanning, adding maintenance and transparency concerns.
38%
Total Score
33
67
67
The package has only one release, published nearly 5 years and 10 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months. Combined with the single historical release, this indicates no recent maintenance capacity.
Only one registry account has publish access. Because the repository is user-owned rather than organization-backed, this indicates a thin publishing base and limited apparent continuity.
The artifact and repository each contain only composer.json and one source file. This is a transparent, minimal layout, but it also offers little evidence of testing, documentation, or project maturity.
The linked repository is owned by a personal user account, not an organization. With only one registry maintainer and no recent activity, there is little visible institutional backing to reduce abandonment risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.