Consumer documentation is brief, and the project has no automated tests or security policy. The package has had no release or commit activity since May 2017, while its repository does not identify or mention this package. MIT licensing and a stable release reduce adoption friction but do not offset the abandonment risk.
35%
Total Score
0
69
75
The package has only two releases, both in May 2017, with no releases in the last 12 months and a latest release nearly nine years ago. This strongly indicates abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since May 2017. No compensating maintenance activity is provided.
The linked repository name does not match the package name and its README does not mention the package, so the repository-to-package relationship cannot be readily verified. This weakens transparency and provenance.
The repository has zero stars and forks and one watcher, providing little supporting evidence of community review or adoption. Popularity is only supporting evidence, so this does not determine the verdict alone.
Composer build tooling is present, but no security-scanning tooling is reported. This is a modest hygiene gap that adds to the limited evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.