Usable with caveats: it has a clear MIT license, matching repository, tests, changelog, and a stable release, but development appears to have stopped in October 2018. Install-time scripts and the absence of security tooling or a security policy add maintenance risk.
57%
Total Score
75
78
67
The package defines post-install and post-update scripts, which increase installation complexity and supply-chain exposure compared with a package without lifecycle hooks.
The package has had no release in nearly eight years and none in the last 12 months, indicating that it is no longer actively maintained despite four historical releases.
There were no commits or active maintainers in the last three months, and the repository's last push was in 2018, leaving current maintenance capacity un demonstrated.
The repository has one star, no forks, and no watchers. This is weak supporting evidence, but low popularity alone does not make a small, otherwise coherent package unsafe to use.
Composer build tooling is present, but no security-scanning tools are configured, leaving a transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.