The package is small and easy to inspect, with a clear MIT license and no install-time scripts. Its long period without releases, minimal project activity, absent tests, and lack of a security policy make future maintenance and change safety uncertain.
42%
Total Score
50
100
67
83
The latest release was over four years ago, and there have been no releases in the last 12 months. This is strong evidence of abandonment risk despite a historically regular early cadence.
The artifact includes a README, which gives consumers basic context, but it has no tests or changelog. The missing tests and changelog are not packaging faults on their own, while the short 57-character README limits consumer guidance.
There are no open issues or pull requests and no recent issue or pull-request activity. While this indicates no visible backlog, it also provides little evidence of an active maintenance process.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these figures provide no meaningful community or maintainer support signal.
Composer is used as the build tool, which is appropriate for the package, but no security scanning tools are configured. This is a hygiene gap that adds to the limited maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.3 | — | — |
imangazaliev/didom Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.