The focused dependency set, readable documentation, and included tests make the package straightforward to evaluate. Its source remains available and licensed, but the age of the last release and lack of recent project activity make long-term compatibility a liability.
40%
Total Score
25
100
81
83
The package has had no release in nearly seven years, despite 14 releases overall; that long gap is strong evidence of abandonment risk for a dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the nearly seven-year release gap and indicating no current maintenance capacity.
There are no open issues or pull requests and no activity in the last month; while this can mean the project is quiet, it also supports the broader inactivity concern.
Composer is used for builds, but the repository reports no security scanning tools; this is a modest transparency and maintenance-hygiene gap.
The repository has no security policy, leaving no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.