The MIT licence, matching repository, clear README, and zero runtime dependencies make adoption straightforward. However, this package has had no maintenance for nearly 11 years, leaving its old 0.1.1 release a substantial abandonment risk.
38%
Total Score
0
100
64
100
There has been only one release, published nearly 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need compatibility or security updates.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the nearly 11-year-old release history. The linked repository is real, but it provides no evidence of current maintenance.
Composer is used as the build tool, but no security scanning tools are present. This is a hygiene gap that matters somewhat for a validation library, though it is secondary to the much older maintenance record.
The repository is not archived, which is a modest positive; however, its last push was nearly 11 years ago, so this does not offset the observed lack of maintenance.
Version 0.1.1 is not a stable-major release, which adds some maturity uncertainty; its non-prerelease status provides only limited compensation given the absence of subsequent releases.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.