The package is documented enough to understand and has a matching source repository. Its maintenance and security practices are too thin for a dependable long-term dependency, so pinning this exact version is preferable.
38%
Total Score
50
78
83
The last of only three releases was published about 12 years ago, with no releases in the past 12 months. This is strong evidence of abandonment, despite the package reaching a stable 1.0.1 release.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide no meaningful community signal to offset the maintenance concerns.
Composer is used as a build tool, but no security-scanning tooling is present. The absence is a modest supply-chain hygiene gap rather than evidence of an unsafe release.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap for a package that may be embedded in applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.