Clear licensing, a useful README, repository tests, and a security policy support transparency. The package is deprecated, its repository is archived, and no commits were recorded in the last 3 months; choose an actively maintained replacement.
15%
Total Score
50
100
58
83
Packagist marks the entire package as abandoned, with no replacement listed. Package-wide deprecation is a severe adoption risk that outweighs its otherwise clear metadata.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This provides direct evidence of absent recent maintenance.
The linked repository is archived, indicating the source project is no longer intended for active development. Its recorded push date does not compensate for the archived status.
The package has only 5 releases across roughly 6 years, with no releases in the last 12 months and a median interval of about 425 days. This is a sparse maintenance history, though the recent 3.0.1 release provides some evidence of prior activity.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. Its one action reference is unpinned, a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.