The package is small, clearly scoped, licensed, and has release notes for this version. Its minimal dependency surface and organization-backed repository help, but the project has no recent maintenance activity.
40%
Total Score
63
100
75
83
This package has only one release, published about 10 years ago, with none in the past 12 months. That strongly raises abandonment risk, despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap. This is substantial evidence of inactive maintenance.
There are no open issues or pull requests and no recent issue or pull-request activity. This provides no evidence of active community maintenance, though it may also reflect the package's small scope.
The repository has one star, zero forks, and one watcher. This is weak supporting evidence and indicates limited adoption, but popularity alone does not determine health.
Composer is used for builds, but no security-scanning tooling is present. The missing scanner is a hygiene gap rather than a standalone dependency-blocking risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.