Usable with caveats: the package is stable, licensed, transparently backed by the matching Litstack organization, and has no install-time scripts, but it has had no release or commit activity for over three years. Its tiny user footprint and lack of security policy increase maintenance risk.
58%
Total Score
50
100
78
88
There were no commits and no active maintainers in the last three months, indicating that maintenance has effectively stopped recently and increasing abandonment risk.
The package has four releases since March 2022, but none in the last 12 months and its latest release was over three years ago. This is a meaningful sign of possible abandonment for a dependency.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no external adoption signal to offset the stale activity.
Composer build tooling is present, showing a basic build setup, but no security scanning tools are configured, leaving a transparency and maintenance gap.
The linked repository is not archived, but its last push was over three years ago; the non-archived status is positive while the age of the last update remains consistent with the maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.