Apache-2.0 licensing, a matching repository, and a documented GitHub release provide useful transparency. The native Linux-oriented dependency profile and lack of security tooling add adoption friction, while the project shows little evidence of ongoing care.
42%
Total Score
0
50
63
75
The package has had only 3 releases, all concentrated between April 29 and May 1, 2023, with none in the last 12 months. That long release gap is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no release for over three years. No provided signal demonstrates compensating maintenance activity.
The package requires PHP FFI, pcntl, mbstring, POSIX, and sockets extensions, making adoption platform-specific and operationally demanding. This is a real compatibility constraint rather than evidence of poor maintenance.
The release includes GitHub release notes for version 0.1.2, which documents the version. The repository reports no tests, and the published artifact has no README; for a library, that weakens maintenance and consumer transparency.
The repository has 1 star, 0 forks, and 1 watcher, so there is little visible community support to compensate for the lack of recent maintenance. Popularity is only supporting evidence, not the primary reason for the score.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.