The package has useful documentation, tests, an MIT license, and no runtime dependencies. Its missing security policy and prerelease status add uncertainty beyond the long maintenance gap.
38%
Total Score
0
100
71
75
The package has had 5 releases since March 2014, but no release in the last 12 months; its latest release was over 12 years ago, indicating severe abandonment risk.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the repository's last push over 12 years ago and indicating no current maintenance capacity.
Composer is used for the build, but no security-scanning tooling is present. The missing scanning is a hygiene weakness, not evidence that the release is unsafe by itself.
The repository has no published security policy, reducing transparency about vulnerability reporting and response for a library that may be embedded in applications.
The assessed version is still a prerelease, and 80% of recent releases were prereleases. This lowers confidence in maturity and long-term compatibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.