The package is clearly identified, MIT-licensed, and documented with a consumer-facing README. Its small dependency set and lack of install-time scripts reduce installation risk, though the absence of tests and security tooling limits confidence.
38%
Total Score
50
100
75
75
The latest release was in October 2018, nearly eight years ago, with no releases in the past 12 months. This strongly raises abandonment risk despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and providing no evidence of ongoing maintenance.
The repository has zero stars and forks and only two watchers, offering little supporting evidence of broad adoption or community resilience. Popularity is secondary, but this adds to the limited maturity evidence.
Composer is used for builds, but no security scanning tools were detected. That is a modest transparency and hygiene gap, not a substitute for the stronger maintenance concern.
The repository has no security policy, leaving vulnerability reporting guidance unspecified. This is a minor transparency gap for a package with otherwise clear ownership.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
linkorb/boost Version ^1.0 | — | — |
symfony/expression-language Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.