Risky to adopt for new projects: the package has had no release or repository activity since January 2018. It is licensed, documented, tested, and not deprecated or archived, but its long abandonment gap outweighs those strengths.
48%
Total Score
25
100
71
83
The latest release was over 8 years ago, with no releases in the last 12 months and only three releases overall. This is strong evidence of an unmaintained dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no activity since January 2018.
The repository is owned by an organization, which provides some backing context, but the zero recent commits and old last push show no current maintenance capacity.
The repository has zero stars and only two forks. Popularity is supporting evidence rather than a verdict, but these figures provide little additional confidence in ongoing community support.
Composer is used for builds, but no security scanning tools are present. This is a transparency gap, though it is secondary to the much larger maintenance concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.