The MIT license, release notes, and matching repository make the project understandable to consumers. Its single-maintainer setup and lack of security scanning add modest operational risk, with no newer release to offset them.
38%
Total Score
25
79
50
The package is about 10 years and 9 months old, with its latest release in January 2016 and no releases in the last 12 months. This is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being about 10 years ago. No provided signal shows current maintenance capacity.
Only one registry account can publish the package, leaving a thin publishing base. The small, user-owned project provides no evidence of broader maintainer capacity to offset that concern.
The project uses Composer for builds, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy. For this small, old plugin that is a hygiene gap, although it does not independently establish that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.