The MIT license and lack of install-time scripts make the package straightforward to adopt. Its minimal project footprint, single maintainer, and long absence of releases or repository activity make future fixes and support uncertain.
38%
Total Score
50
50
75
The package has only one release, published about 7 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
Only one registry maintainer is listed, leaving a thin publishing base and limited apparent continuity if that maintainer stops supporting the package.
A README is present, and the absence of tests or a changelog in the published artifact is normal packaging practice. The README is very short, so it offers limited consumer guidance.
Composer is used for builds, but no security scanning tools are reported. This is a modest hygiene gap and does not offset the stronger maintenance concerns.
The repository is not archived, but it was last pushed about 7 years ago, which provides little evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.