The package is clearly licensed, documented, and has a matching source repository with release notes for this version. Its single-maintainer base and absent security policy leave less resilience if maintenance needs resume.
62%
Total Score
50
79
75
Only one registry account has publish access. The matching user-owned repository provides some continuity, but the narrow publishing base increases single-person dependency risk.
The package has existed for over 12 years with nine releases, but has had no registry release in nearly five years and none in the last 12 months. This is a meaningful maintenance concern, although the package may be stable and intentionally quiet.
There were zero commits and zero active maintainers in the preceding three months, indicating that maintenance has effectively stopped rather than merely slowed.
Composer is used as a build tool, but no security scanning tooling is reported. This is a modest transparency and maintenance-process gap, not a severe risk by itself.
The linked repository is not archived, but its last push was September 29, 2021, consistent with the prolonged inactivity seen in the release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.