The MIT license, focused dependency set, clear README, and matching repository provide a usable foundation. However, the package has had no release or commit activity since February 2017, with no tests, changelog, security policy, or security scanning.
38%
Total Score
0
100
69
83
Only two releases were published, both in February 2017, and there have been no releases in more than nine years. This is strong evidence of abandonment for a package intended to support development tooling.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since 2017.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption or review signal alongside the long inactivity period.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency gap rather than proof of unsafe code.
The repository is not archived, which avoids an explicit withdrawal signal, but its last push was on February 23, 2017 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.