Usable with caveats: the package is licensed, documented, tested, and backed by a matching organization repository, but it has had no release or commit activity for about seven years. Its small repository footprint and lack of a security policy add maintenance concerns.
57%
Total Score
50
100
67
90
The package has only three releases, all concentrated in February 2019, with no releases in the last 12 months and no subsequent release activity shown. This is a substantial maintenance and abandonment concern.
There were zero commits and zero active maintainers in the last three months, with the repository otherwise showing no newer activity. This is a strong abandonment concern for a library that may need compatibility or security fixes.
The repository is not formally archived, but its last push was in February 2019, consistent with the absence of releases and indicating that the project may no longer be maintained.
The repository has only 6 stars, 0 forks, and 2 watchers, providing little evidence of a broad user or contributor community to compensate for the long inactivity.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tool is configured. The absence of scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.