Its three-file tree and single registry maintainer offer little evidence of ongoing development. MIT licensing, an unarchived repository, and organization ownership provide some reassurance, but not enough for a dependable new dependency.
42%
Total Score
50
79
50
The package has only two releases, and the latest was published in January 2021; there have been no releases in more than five years. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no observed ongoing maintenance.
The published artifact contains only three files, including one source file. That may fit a very small library, but it provides little evidence of mature project structure.
Composer build tooling is present, but no security-scanning tooling was detected. This is a maintenance and transparency gap, though not severe by itself.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.