The package includes extensive documentation and tests, with a small dependency footprint and clear organization backing. Its MIT declaration and matching source repository improve transparency, but they do not offset package-level deprecation and years without development.
20%
Total Score
50
58
50
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk because it signals that future maintenance should not be expected.
Only two releases exist, and the latest was published in November 2016; there have been no releases in roughly nine years. This strongly indicates abandonment for a dependency released as version 0.1.1.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this shows that the source project is not being actively maintained.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a secondary transparency gap alongside the stronger abandonment signals.
Version 0.1.1 is not a stable major release, so the package has not reached a mature 1.0 API milestone. This adds compatibility uncertainty, although the version is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.