Documentation is minimal, and the project has no security policy or scanning. It is not deprecated or archived, but the long release gap makes this version a weak dependency choice.
42%
Total Score
50
72
83
The package has had no release in nearly three years, with zero releases in the last 12 months. Its four-release history shows an earlier cadence but does not offset the current abandonment risk.
A README is present, and the absence of tests and a changelog in the published artifact is normal packaging practice. The README is very short and describes the SDK as incomplete, limiting consumer guidance.
The repository is owned by an individual user rather than an organization, so the small registry and repository footprint offers no visible organizational backing.
The repository has zero stars and forks and only one watcher, providing little evidence of community validation or support. Popularity is supporting evidence, but this reinforces the maintenance concern.
Composer is used for builds, but no security scanning tools are configured. The absence of scanning weakens supply-chain hygiene for a package intended for dependency use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.