It has a clear BSD-3-Clause license, a usable README, and a small runtime dependency footprint. The repository is tiny and has no security policy or automated security scanning, so long-term support is difficult to verify.
44%
Total Score
50
100
79
50
The package has only 3 releases, all concentrated in June 2017, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the short early release interval.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has received no recent development. This materially increases abandonment risk.
The repository has 2 stars and 2 forks, indicating limited external adoption and review. Popularity is supporting evidence only, but it provides little compensating evidence for the maintenance gap.
Composer is used for build and dependency management, but no security scanning tooling was detected. The missing scanning is a modest transparency and maintenance concern, not a standalone adoption blocker.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a genuine but secondary weakness for a small, inactive library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.