The MIT license and dependency-free design reduce adoption friction. Its small 0.x release history and no activity since March 2016 leave maintenance and compatibility risks unresolved. Use only when its narrow demo-oriented scope fits and you can accept the lack of updates.
40%
Total Score
25
100
50
The package has only 3 releases, with none in the last 12 months, and its latest release was over 10 years ago. This strongly suggests abandonment risk for a dependency, despite the possibility that its narrow scope is stable.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring over 10 years ago. This is a substantial unresolved maintenance concern.
Only one registry maintainer is listed, and the project is backed by an individual repository owner rather than an organization. That leaves limited visible continuity if the maintainer stops supporting it.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and hygiene gap, secondary to the much older activity data.
The latest version is 0.1.0 rather than a stable major release, so compatibility guarantees are limited. Its lack of prerelease churn is mildly positive but does not offset the very early version status.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.