Risky to adopt without a strong reason: this package has had no release or repository activity since February 2020. It is small, licensed, and backed by repository tests, but its long-standing inactivity and limited project hygiene make future fixes uncertain.
45%
Total Score
0
100
67
50
The package has only one release, published about 6 years ago, with no releases in the last 12 months. That is strong evidence of an unmaintained dependency, although the stable 1.0.0 version avoids prerelease instability.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release gap. The repository is not archived, but there is no observed recent maintenance to offset the concern.
The published artifact has no README, which is a real usability and transparency gap for a library consumers must integrate. The source repository does contain tests, providing some compensating evidence about basic project quality.
The repository uses Composer, which provides ordinary build/package tooling, but it has no security scanning tools. This is a modest transparency and maintenance gap, especially for a package with no recent activity.
The repository has no security policy. For a small, inactive library this reduces clarity about vulnerability reporting and response, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.