The package is small and clearly identified, with a README, release notes, and a simple dependency profile. Its repository is not archived and the package is not deprecated, but ongoing maintenance evidence is absent.
40%
Total Score
50
100
75
50
Only two releases were published, with the latest in March 2019 and none in more than seven years. This is strong evidence of abandonment for a package that may need ongoing compatibility maintenance.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the last push being in July 2019. The long-standing lack of activity materially raises abandonment risk.
Composer is used as the build tool, but no security scanning tooling was detected. This is a modest transparency and hygiene gap, not a standalone reason to reject the package.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a minor transparency gap for a package intended to run in applications.
The assessed version is a release candidate and the latest stable version reported is 0.8, so the package does not present a mature stable release line. This adds compatibility uncertainty alongside the maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.