The MIT license, matching repository, and clear usage guide make the package transparent to evaluate. Its release and maintenance record provide no evidence of current support, while security oversight is also limited.
39%
Total Score
0
67
75
This is the package's only release, published nearly ten years ago, with no releases in the last twelve months; that is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long-stalled release history.
The repository has zero stars and forks and only one watcher. Popularity is not decisive for a small package, but it offers no supporting evidence alongside the inactivity.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented; this is a secondary transparency gap for an otherwise small package.
The package remains at v0.0.1, so it has not demonstrated a mature stable release line despite not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
enniel/epochta Version ~0.0.1 | — | — |
psr/http-message Version ~1.0.1 | — | — |
illuminate/support Version ~5.1 | — | — |
illuminate/notifications Version ~5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.