It has an MIT license, tests, release notes, and no runtime dependencies. The project is minimal, but its current maintenance state makes a new dependency hard to justify.
42%
Total Score
25
100
75
83
The package has only two releases, with the latest published in April 2015 and none in the last 12 months. This long release gap is strong evidence of abandonment, despite the package remaining available.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and indicating no observable ongoing maintenance.
The package is backed by a matching individual-owned repository rather than an organization. That is valid ownership context but provides limited evidence of maintenance capacity.
The repository has one star, zero forks, and one watcher. This is weak supporting evidence of maturity, although popularity alone is not decisive.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest project-hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.