Licensing is clear, dependencies are minimal, and the package has no install-time scripts. Its last release and repository push were about 9 years ago, with no recent activity, making abandonment the main concern.
40%
Total Score
50
100
64
83
The package has only 4 releases, and its latest release was about 9 years ago; it has had no releases in the last 12 months. This strongly increases abandonment risk.
The repository is owned by an organization, which provides some backing context. However, the observed release and repository activity remains inactive, so this does not compensate for the maintenance concern.
The repository has 0 stars and 0 forks, providing little supporting evidence of community adoption. Popularity is not decisive, but it offers no compensation for the long inactivity period.
Composer is used as a build tool, but no security-scanning tools are present. The missing scanning is a minor hygiene gap rather than evidence of abandonment on its own.
The linked repository is not archived, which is a modest positive, but its last push was about 9 years ago and does not offset the stale release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.