The package contains only a README and Composer metadata, providing little evidence of a mature library. Its source repository lacks a security policy and does not identify the package in its README. The non-archived repository and non-deprecated release do not offset the maintenance and licensing gaps.
28%
Total Score
50
75
50
Neither the package nor the repository provides a license declaration or license file. This creates a real adoption and redistribution concern.
The artifact and repository each contain only three files: .gitignore, README.md, and composer.json. That may be a minimal package, but it provides little transparency about implementation or maintenance.
This package has made only one release, on July 14, 2017, with no releases in the following 9 years. That strongly indicates abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and providing no evidence of current maintenance.
The linked repository name does not match the package name and its README does not mention the package, so the repository may not clearly belong to this release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.