Unfit to use for new projects: the package explicitly says it is deprecated, no longer maintained, and has known unfixed bugs. Although the repository is intact and the release is licensed and tested, the lack of recent commits and stated replacement make it a poor dependency choice.
22%
Total Score
0
67
83
The README explicitly says the package is deprecated, no longer maintained, and has known bugs that will not be fixed; its tests and documentation do not compensate for that abandonment.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the README's statement that maintenance has ended.
The package has existed since 2014 with 11 releases, but only one release in the last 12 months does not outweigh the explicit statement that the project is no longer maintained.
Composer is used for the project build, but no security scanning tooling is present; this is a secondary hygiene gap for a package already identified as unmaintained.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this adds a transparency gap but is not the primary reason to reject the package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.