The package is small and clearly documented, with a matching repository and MIT license. It has no security scanning, and its only release was over 11 years ago, so maintenance risk is substantial.
42%
Total Score
0
100
67
75
This is the package's only release, published over 11 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the single historical release, this indicates no current maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. The build setup is a modest positive while the missing scanning leaves a hygiene gap.
The repository has no security policy. For a small package this is not severe by itself, but it reduces transparency for reporting and handling future issues.
The assessed version is a non-prerelease 0.1.0, which avoids prerelease instability, but the package has no newer version to demonstrate ongoing development.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.