It has an MIT license, tests, and a matching repository, but the documentation is still a package-template draft. Its single-user ownership and lack of security tooling add little evidence of ongoing care.
32%
Total Score
25
69
75
The package has had only two releases, both in October 2017, and none in the past nine years. That prolonged release silence is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, with its last push in October 2017. This confirms that the release gap reflects inactive development rather than merely slow publishing.
Only one registry publishing account is listed, which is a thin maintainer base for a user-owned project. No organizational backing is shown to compensate for that concentration.
The artifact includes tests and a README, but the README still contains unfilled template instructions and placeholder project text. That weakens transparency and suggests the package was published before being finished.
Composer build tooling is present, but no security-scanning tools are reported. This provides little evidence of ongoing supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.