The complete source tree, tests, release notes, and matching repository support transparency. However, there have been no releases or commits for nearly 13 years, and the project has no security scanning or policy.
42%
Total Score
25
100
81
88
The package has had only two releases, both in September 2013, with none in the last 12 months. Nearly 13 years without a release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity for nearly 13 years.
The repository is owned by an individual account rather than an organization, so the single registry maintainer does not have organizational backing to compensate for inactivity.
Composer build tooling is present, but no security scanning tools were found. For a package this old, the missing scanning adds a modest transparency and maintenance concern.
The repository has no security policy. This is a maintenance and disclosure gap, though it is less important than the long-established lack of release and commit activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.