The package is small and clearly identified, with an MIT license, README, stable version, and no install-time scripts. Its limited tooling and lack of a security policy provide little additional assurance for a dependency this old.
38%
Total Score
50
100
81
83
Only two releases were published, both in May 2014, with no releases in the past 12 years. This is strong evidence of abandonment for a package developers may need to rely on over time.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the last push occurring in May 2014. The stable release does not compensate for the absence of current maintenance.
There is one open issue, while no issues or pull requests were opened or closed recently. This gives no evidence that reported problems are actively handled.
Composer build tooling is present, but no security-scanning tools are configured. That is a modest hygiene gap rather than a severe risk on its own.
The repository has no security policy. This is a transparency and response-process gap, although it is less important than the package's much older maintenance record.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.