Its MIT license, clear README, and intact repository make adoption straightforward. The single-maintainer project has had no commits or releases for over five years, so future fixes are uncertain.
55%
Total Score
50
88
75
Only one registry maintainer is listed, leaving limited visible publishing capacity. The linked repository is owned by the same individual, which provides some continuity but not much redundancy.
The package has had no releases in the last 12 months, and its latest release was over five years ago. This is strong evidence of limited ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment concerns.
The project uses Composer build tooling, but no security scanning tools were detected. For a small legacy JavaScript plugin this is a modest hygiene gap rather than a severe dependency risk.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap, though not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.