The six-file artifact has a focused README and no install-time scripts. Repository identity is supported by the README mention, but the project lacks security scanning and has little visible community support.
42%
Total Score
0
69
100
The latest release was published in June 2020, and there have been no releases in roughly six years. That strongly increases abandonment risk for a package with no newer maintenance evidence.
The repository has recorded no commits or active maintainers in the last three months, consistent with its last push being roughly six years ago. The long-standing inactivity materially lowers confidence in ongoing maintenance.
The manifest declares the package proprietary, with no detected license and no license file in either the artifact or repository. This creates a significant transparency and adoption concern for an open-source dependency.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful external evidence of adoption or review.
Composer is used for the build, which is appropriate, but no security scanning tooling is present. For this small package that is a hygiene gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.