The MIT license, matching repository, and release notes improve transparency. The implementation is very small, with no tests or security policy, so future support is uncertain.
38%
Total Score
25
69
75
Only two releases were published, both in September 2016, with no release in nearly 10 years. This strongly raises abandonment risk despite the package remaining available.
The repository has recorded no commits or active maintainers in the past three months, and its last push was in 2016. There is no observed recent maintenance to offset the stale release history.
The package has one registry maintainer, limiting observed publishing capacity. The linked repository is also owned by an individual, with no organization backing shown.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these figures provide no supporting evidence of active adoption or community support.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap for a package with no recent activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.