The repository is unarchived and correctly matches the package, with organization backing and a useful README. It has no security policy, no tests, and the license declaration conflicts with the repository's OSL-3.0 file.
18%
Total Score
75
58
75
Packagist marks the entire package as abandoned, making this release a severe dependency risk even though a replacement is listed.
Only two releases exist, with no releases in the last 12 months and roughly 21 months since the latest release, indicating substantial abandonment risk.
A license file exists, so the project is licensed, but the manifest declares MIT while the repository license file is detected as OSL-3.0; that mismatch needs clarification.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's abandoned status.
The repository has no security policy, leaving vulnerability reporting and response practices undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.