The brief documentation and missing security policy leave limited guidance for maintainers and consumers. Its narrow dependency surface and clear usage example reduce integration friction, but this release needs replacement planning rather than long-term reliance.
38%
Total Score
25
100
67
75
The package has had only one release, published in January 2017, with no releases in the last 12 months; this is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The linked repository is owned by an organization, providing some ownership context, but this does not compensate for the observed lack of recent releases or commits.
Composer is used for the build, but no security-scanning tooling is present; this is a modest maintenance and assurance gap alongside the inactive project.
The repository is not archived, which is a positive sign, but its last push was in October 2018 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.