Risky to adopt: it has had only one release, with no updates for about five years and no recent repository activity. The package is small and clearly licensed, but its lack of maintenance evidence makes it a liability for a dependency.
42%
Total Score
25
100
72
88
The package has only one release, published about five years ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance or compatibility work.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is strong evidence that development has stopped or is dormant.
The repository is owned by an individual user rather than an organization, so the package appears to rely on a single project owner for continuity. This provides limited backing if the maintainer stops contributing.
The repository has zero stars and forks and only one watcher. Low popularity is not decisive for a small package, but it offers no supporting evidence of community adoption or review.
Composer is used as the build tool, but no security scanning tools are present. This is a transparency and maintenance gap, though the repository has no workflows that would otherwise increase workflow-related risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.