The stable 1.0.0 package is licensed, tested, documented, and has only one runtime dependency. Organization backing and a clean release setup help, but maintenance evidence is too old for a current dependency.
43%
Total Score
75
100
64
50
This package has had only one release, published in March 2020, with no releases in the following six years. That strongly increases abandonment risk for a dependency adopted today.
Only one account has registry publishing access, but the organization-owned repository provides compensating project backing. Administrative access alone does not demonstrate active maintenance.
The repository has zero stars and forks and two watchers. Low popularity is only supporting evidence, but it provides no additional confidence in long-term community support.
Composer build tooling is present, but no security scanning tools were detected. This is a secondary hygiene gap rather than the main adoption risk.
The repository is not archived, which avoids a stronger abandonment signal, but its last push was also in March 2020 and does not offset the stale release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.