Usable with caveats, but maintenance appears stalled: there have been no releases or repository commits in over two years. The package is small, clearly licensed, not deprecated or archived, and has organization backing, which keeps it from being unfit to use.
54%
Total Score
75
80
75
The package has only two releases, both in its first 34 days, and none in the last 12 months; the latest release was over two years ago. This is a meaningful maintenance concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository uses Composer build tooling, but has no security-scanning tools. This is a modest transparency gap, though the small package and lack of workflow activity limit the practical concern.
No repository security policy was found. This is a transparency gap, but it is less significant for a small, inactive package with no reported issue activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
carbon/eel Version ^2.14 | — | — |
garagist/fontawesome Version ^0.1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.