The package offers almost no usage guidance, and the repository has no security policy or scanning tools. Its last release was in May 2016, leaving current maintenance and compatibility uncertain.
40%
Total Score
64
75
The six-release history ends on May 30, 2016, with no releases in roughly 10 years. That strongly increases abandonment and compatibility risk for a dependency.
The artifact includes a README, but it is only 9 characters and provides no meaningful integration guidance. The missing tests and changelog are normal packaging practice and do not add concern.
The repository has 1 star, 0 forks, and 1 watcher, indicating very limited visible adoption or review. Popularity is only supporting evidence, but it provides little compensating confidence for the long inactivity.
The repository uses Composer, which supports reproducible project structure, but no security scanning tools are present. For a package intended to be deployed, that leaves an avoidable transparency and maintenance gap.
No security policy is provided, so there is no documented process for reporting or handling vulnerabilities. This is a meaningful transparency gap, though it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.