The package is clearly identified, has a usable README, and includes release notes for this version. Its single-contributor maintenance model, license mismatch, absent security policy, and workflow hygiene leave meaningful adoption risk.
62%
Total Score
50
81
75
The artifact declares GPL-2.0-or-later but contains a detected MIT license file, so consumers may face ambiguity about the applicable license despite having a license file.
The package has only two releases across about 7 years and a median gap of about 7.6 years, indicating a very limited release track record despite one release in the last 12 months.
All recent commits came from one contributor, leaving maintenance dependent on a single person and limiting continuity if they stop responding.
There was one commit in the last 3 months from one active maintainer, showing some maintenance but a very low activity level.
The project uses Composer build tooling, but no security-scanning tools were detected; the missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.