Tests and a usable README provide some adoption support, while the single maintainer and absent security tooling limit ongoing oversight. The package has seen no releases or repository commits for about 10 years, so maintenance risk is substantial.
38%
Total Score
50
100
75
88
The last release was about 10 years ago, with no releases in the past 12 months and only three releases overall. This is strong evidence of abandonment risk for a dependency that may need fixes or compatibility updates.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap. No newer activity is provided to offset that maintenance concern.
The registry lists one maintainer, which creates a thin ownership base. The linked repository is user-owned rather than organization-backed, so no provided evidence compensates for the limited continuity.
The repository has zero stars, one fork, and one watcher, offering little supporting evidence of broad review or community maintenance. Popularity is only supporting evidence, so this reinforces rather than determines the result.
Composer build tooling is present, but no security scanning tools are configured. That leaves a transparency and maintenance gap, though it is less severe than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.