The narrow scope and straightforward Composer setup keep integration simple. Its tiny audience and absent security process provide little evidence of ongoing support, so pinning this release carries long-term maintenance risk.
38%
Total Score
25
100
69
83
The last release was in November 2018, and there have been no releases in roughly seven years and ten months. This is strong evidence of an effectively abandoned package despite its three-release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of current maintenance.
Only one registry publishing account is listed, and the project backing identifies an individual owner rather than an organization. This leaves a thin maintenance base when combined with the lack of recent activity.
Composer is used as a build tool, which supports reproducible package handling, but no security-scanning tooling is present. The missing scanning is a modest hygiene gap rather than evidence of immediate unfitness.
The linked repository is not archived, so it has not been formally withdrawn. Its last push in November 2018 still indicates that practical maintenance has stopped.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.