The package is licensed, has no install-time scripts, and keeps its runtime dependency surface minimal. Documentation is absent, and the repository has no security policy or automated security scanning, which makes long-term maintenance harder to evaluate.
35%
Total Score
100
58
75
Only three releases were published, with the latest in October 2018 and none in the last seven years. That prolonged release silence is strong evidence of abandonment risk for a package developers may need to maintain or update.
The artifact has no README, and the repository reports no tests or changelog. Missing tests and changelogs can be normal for a tiny package, but the absent consumer documentation is a real integration gap.
Composer is used for the build, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The linked repository is not archived, which avoids an explicit abandonment marker, although its last push was in November 2018 and the release history indicates the project is inactive.
The repository has no security policy. For a small telemetry library this is not independently severe, but it reduces transparency around reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.