It includes a README, tests, a small dependency surface, and no install-time scripts. Those strengths do not offset the package being withdrawn and the source repository being archived, with no releases or commits for nearly seven years.
12%
Total Score
0
100
50
83
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct maintenance and adoption warning for the assessed release.
The package has only one release, published in November 2019, with no releases in the last 12 months. Nearly seven years without another release indicates severe abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms there is no recent development activity to compensate for the old release.
The linked repository is archived, and it was last pushed in March 2021. An archived source project is no longer an active maintenance channel.
Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a minor hygiene gap, while the build tooling itself is appropriate.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.