The package has a clear README, matching repository, and minimal runtime dependencies. Its organization backing and clean workflow audit help, but there is no license and no release or repository activity for about six years.
42%
Total Score
75
100
57
67
Only one release exists, published about six years ago, with no releases in the last 12 months. That is strong evidence of an unmaintained dependency.
Neither the package nor the repository provides a declared license or license file. This creates a material legal and adoption concern.
There are no open issues or pull requests and no recent activity. While this may reflect a small project, it provides no evidence of ongoing maintenance.
The repository has one star and no forks, so there is little community evidence to compensate for the long period without maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a minor transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.