The package is small and easy to inspect, with a README, stable version, one runtime dependency, and no install-time scripts. Its single release is over 12 years old, repository work stopped over 11 years ago, and it has no license or tests, leaving substantial maintenance and reuse risk.
40%
Total Score
0
100
69
88
There has been only one release, published over 12 years ago, with no releases in the last 12 months. This strongly indicates abandonment risk despite the package remaining stable.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the last push being over 11 years ago. No provided signal shows current maintenance capacity.
Neither the package nor the linked repository declares or includes a recognized license. That creates a real legal and transparency problem for adoption.
Composer is used as the build tool, showing basic project structure, but no security scanning tools are present. For this small package that is a minor hygiene gap rather than a primary adoption blocker.
The repository is not archived, but its last push was over 11 years ago. The non-archived status is mildly reassuring administratively, while the age of the last activity remains the more important evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.