Its MIT license and minimal dependency footprint make evaluation straightforward. The repository is not archived and the release is stable, but the project shows little evidence of ongoing maintenance or verification.
35%
Total Score
50
100
69
75
This is the only release, published in April 2018, with no releases in the last 12 months; the package has had no demonstrated release maintenance for over eight years.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in April 2018 and indicating a strong abandonment risk.
The package includes a README, but it is only 14 characters long and provides little consumer guidance. Missing tests and changelog files are normal for published artifacts and are not concerns here.
The linked repository name does not match the package name and its README does not mention the package, so the source-to-package relationship is not clearly established.
Composer build tooling is present, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap alongside the inactive project.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.