The release is clearly licensed and includes a readable package artifact. However, it has seen no release or commit activity for about 12 years, and the linked repository neither matches the package name nor mentions it, leaving maintenance and ownership uncertain.
32%
Total Score
0
50
50
Only two releases were published, both in July 2014, with no releases in the last 12 months; about 12 years without a release is strong abandonment evidence.
There were no commits and no active maintainers in the last three months, consistent with the roughly 12-year maintenance gap and materially increasing compatibility risk.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish package ownership.
The repository has only 3 stars, 0 forks, and 1 watcher; popularity is supporting evidence rather than decisive, but it offers little evidence of community support.
Composer build tooling is present, but no security scanning tooling was found; this is a modest transparency and maintenance gap for a package with no recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.