The small codebase is documented, MIT-licensed, and has no install-time scripts. Its maintenance and security coverage are thin, making a currently maintained alternative safer.
38%
Total Score
0
67
75
The package has had only two releases, both in March 2017, and none in over nine years. That long release gap is strong evidence of abandonment for a dependency intended for ongoing use.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push being over nine years ago. No provided maintenance signal compensates for this inactivity.
The repository has zero stars and one fork, providing little supporting evidence of adoption or community review. Popularity is not required for health, but there is no visible community signal to compensate for the maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a meaningful transparency gap alongside the absence of recent maintenance.
The latest release is v0.1.1 rather than a stable major release, so the package has limited maturity evidence. Its non-prerelease status is mildly reassuring but does not offset the age and inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.22 | — | — |
symfony/console Version ^3.2 | — | — |
symfony/var-dumper Version ^3.2 | — | — |
cypresslab/gitelephant Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.