MIT licensing, a tiny runtime dependency set, and a matching repository make adoption straightforward. There is no security policy or automated security scanning, so ongoing oversight is limited.
38%
Total Score
50
100
78
83
The package has had only two releases, both on the same day in January 2016, with no releases in the last 12 months. This is strong evidence that maintenance has stopped.
The repository has recorded zero commits and zero active maintainers in the last three months, and its last push was in December 2016. The long period without source activity materially increases abandonment risk.
The repository has two stars, zero forks, and one watcher. Low adoption provides little external evidence of active maintenance, but popularity alone is not decisive.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, though it is less significant than the project's prolonged inactivity.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a moderate transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.