The package has a clear README, an MIT declaration, a small dependency set, and repository tests. Its source is not archived, but the old release leaves compatibility uncertain and makes ongoing support difficult to verify.
38%
Total Score
0
100
69
50
The package has made only one release, on 19 April 2015, with no releases in roughly 11 years. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in 2015. The long inactivity materially lowers confidence in ongoing maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no community-maintenance signal.
Composer is used for builds, but no security-scanning tooling is present. This is a modest transparency and maintenance-hygiene gap, not evidence of an unsafe release by itself.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although the package's long inactivity is the more significant concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.