The codebase is small, has repository tests, uses a declared MIT license, and runs no install-time scripts. Its minimal dependency surface does not compensate for the lack of ongoing project support.
12%
Total Score
50
100
42
100
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry itself signals that maintenance has ended.
The latest release was published about 9 years ago, and there have been no releases in the last 12 months. The five-release history shows a completed, inactive project rather than an actively maintained dependency.
There were no commits and no active maintainers in the last 3 months, consistent with the repository being archived. This provides no evidence of current maintenance capacity.
The linked repository is archived and was last pushed about 9 years ago. An archived source project is a strong indication that fixes and compatibility updates will not arrive.
Composer is used as a build tool, but no security-scanning tooling was detected. The missing scanner is a minor hygiene gap, not the primary reason this release is unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.