The MIT license, readable documentation, tests in the repository, and a matching source project improve transparency. The package has no recent registry releases and is marked abandoned, so adopting it creates substantial maintenance risk.
20%
Total Score
50
100
71
83
Packagist marks the entire package abandoned, with no replacement specified. This is a direct warning against taking a new dependency and outweighs the repository's limited recent activity.
The latest registry release was in April 2022, with no releases in the last 12 months. That long release gap materially increases abandonment and compatibility risk.
The repository and registry are owned by the same individual account rather than an organization. This is consistent ownership, but it provides no organizational handoff capacity.
All recent repository commits came from one contributor, leaving maintenance concentrated in a single person. The matching repository provides some context, but there is no broader contributor base shown here.
The repository recorded only 1 commit from 1 active maintainer in the last 3 months. This shows some activity but does not offset the package's abandoned registry status or long release gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.