No commits or releases have appeared for about 10 years, leaving compatibility and maintenance uncertain. The linked repository also does not name this package or mention it in its README, while the MIT license and focused dependency set are positive.
38%
Total Score
0
100
71
100
The package has only 2 releases, with the latest published about 10 years ago and none in the last 12 months. That long period without releases is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the roughly 10-year release gap and providing no evidence of current maintenance.
The repository name does not match the package name and its README does not mention the package, so the linked source may not clearly belong to this release. This reduces transparency, although the file tree is consistent with the package's namespace.
Composer is used as the build tool, but no security scanning tooling is present. This is a modest transparency gap, secondary to the much older maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.