The linked project has no security policy or scanning, and its README does not identify this package. The stable version and absence of install scripts do not offset the long inactivity.
30%
Total Score
50
33
50
Only two releases were published, both on October 26, 2020, with no release in nearly six years. That is strong evidence of abandonment for a package intended as a dependency.
The package has no declared license, license file, or repository license file. This creates a material legal and adoption risk for downstream users.
The published artifact contains only README.md and composer.json, providing very little transparency about implementation or project contents. The small tree reinforces the uncertainty around what consumers are adopting.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing prolonged inactivity.
The repository name does not match the package name and its README does not mention the package, so the linked source may not clearly belong to this release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.