The package is clearly licensed, has a matching source repository, and provides the complete font files with a README. It lacks a security policy and build security scanning, which leaves less transparency around future maintenance.
52%
Total Score
75
78
75
The five releases were clustered within about 20 minutes, and there have been no releases for nearly eight years. That strongly limits evidence of ongoing maintenance, although a finished font asset may not need frequent updates.
There were zero commits and zero active maintainers in the past three months, consistent with the repository having been inactive since January 2019. This is the main abandonment concern, though the package is a static font collection.
The repository has zero stars and zero forks, with one watcher. Popularity is only supporting evidence, but these counts provide little external evidence of sustained use or review.
Composer is used as the build tool, but no security scanning tools are configured. For a static font package this is a modest transparency gap rather than a severe risk.
The linked repository is not archived, but its last push was on January 11, 2019; the unarchived status does not offset the age of the observed activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.