The MIT license and modest runtime dependency set make the package straightforward to evaluate. Its source repository has no security policy or scanning, and the repository does not clearly identify the package in its README.
38%
Total Score
0
100
67
50
The package has only 3 releases, all concentrated in October–November 2017, with no releases in the last 12 months despite being about 9 years old. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no activity since November 2017.
The published artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. Although missing tests and changelogs can be normal packaging practice, the missing consumer documentation is a meaningful transparency gap for a library.
The repository name does not match the package name and no README package mention was observed. This creates some uncertainty that the linked repository is the intended project, although a name mismatch can be normal for subpackages.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This adds a modest transparency concern but does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/event Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.