Risky to adopt: the package has had no release or repository activity for nearly six years, with no tests or security scanning. It is clearly licensed, documented, and not deprecated, but the long-term abandonment risk is substantial.
42%
Total Score
25
64
83
Only two releases were published, both in September 2020, with no release in nearly six years. That is strong evidence of an abandoned or unmaintained dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The package and repository are owned by the same individual account, so the source linkage is consistent. However, there is no organization backing to offset the very thin apparent maintenance base.
The repository has zero stars, forks, and watchers. Popularity is not required for a healthy small package, but here it provides no supporting evidence against the abandonment concerns.
Composer build tooling is present, but no security scanning tools are configured. For a client handling remote JSON-RPC connections, the missing security checks reduce transparency and ongoing assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.