The codebase is small and easy to inspect, with no install-time scripts or declared deprecation. Organization backing and a stable version reduce uncertainty, but they do not offset the long maintenance gap.
42%
Total Score
100
100
67
83
The package has had no releases in roughly 10 years, with only three releases concentrated on one day in 2016. This is strong evidence of abandonment risk for a dependency, despite the package not being marked deprecated.
The artifact includes a README, but it is only 13 characters long and the project reports no tests or changelog. The GitHub release for this version is a small positive, while the missing tests and minimal consumer documentation limit confidence.
The repository has zero stars and forks and only two watchers, offering little evidence of active community adoption or external review. Popularity is supporting evidence rather than decisive on its own, so this is a modest concern.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. This is a hygiene gap rather than a severe dependency risk.
The repository is not archived, but it was last pushed in July 2016, confirming that the project has been inactive for roughly 10 years. The unarchived status provides little compensation for the absence of recent maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.