The repository is small and easy to inspect, with a clear README and only one runtime dependency. A single maintainer, no security policy, and no security scanning reduce confidence in long-term support. The MIT declaration and lack of install scripts are positives, but they do not offset the absence of recent activity.
34%
Total Score
25
100
67
75
The package has had no releases in the last 12 months, and its latest release was published in May 2018. This long period without updates is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package having been inactive since 2018. No provided maintenance signal compensates for this.
Only one registry maintainer is listed, leaving the project dependent on a single individual for publishing and continuity. The linked repository is also owned by a user rather than an organization, so there is no visible backing to offset that concentration.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community use or review. Popularity is only supporting evidence, so this reinforces the maintenance concern without determining it alone.
Composer is used for the build, but no security scanning tools are present. This is a modest hygiene gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.