Clear documentation, tests, release notes, and an MIT license support adoption. The project has not released or committed anything for about 10 years, and its README labels it work in progress and not recommended for use.
38%
Total Score
0
75
50
Only two releases were published, with none in the last 12 months; the latest release is about 10 years old. This is strong evidence of abandonment risk for a library dependency.
The repository shows no commits or active maintainers in the last 3 months, consistent with the long release gap and indicating no current maintenance capacity.
The repository has no security policy. This is a transparency gap, but it is secondary to the much stronger evidence about the project's age and inactivity.
The assessed release is v0.2.0 and not a stable major release, which adds API and maturity uncertainty; the absence of recent development makes that concern more significant.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.0.* | — | — |
fabiang/sasl Version dev-rspauth | — | — |
react/stream Version ^0.4.3 | — | — |
php-di/php-di Version ^5.3 | — | — |
kadet/keylighter Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.