The package has a stable v1 release and no install-time scripts, but its tiny source tree offers little evidence of ongoing support. Documentation and security coverage are also minimal, so adopting it creates maintenance risk.
38%
Total Score
50
67
83
The latest release was published nearly eight years ago, with no releases in the last 12 months and only two releases recorded. This is strong evidence of abandonment risk.
The registry has one publishing maintainer, and the project is user-owned rather than organization-backed. A single maintainer can be sufficient, but there is little observed capacity for continued support.
The artifact includes a README entry, but it is empty, and the project has no tests or changelog. The lack of tests and changelog is normal for published artifacts, while the empty consumer documentation is a real transparency gap.
The repository has one star, no forks, and no watchers. Popularity is only supporting evidence, but these very low levels provide no meaningful adoption or community support signal.
Composer is used for the build, which is appropriate for a Packagist package, but no security scanning tooling is reported. The tooling is adequate for packaging while offering limited additional security assurance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.