The package has clear licensing and a repository that matches its name. Its last release and repository activity were about two years ago, so adopting it carries meaningful abandonment risk.
45%
Total Score
50
86
75
Only one registry account has publish access, leaving little visible publishing redundancy. This is more concerning alongside the absence of recent release and commit activity.
The package has had no releases in the last 12 months, and its latest release was about two years and four months ago. Earlier releases were frequent, but the prolonged pause is a maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no recent activity to offset the abandonment concern.
The repository uses Composer for builds, showing basic build tooling, but it reports no security-scanning tools. That is a modest hygiene gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is secondary to the stronger inactivity signal.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.