Documentation is present, licensing is clear, and the dependency footprint is minimal. The only release dates from May 2017, while the repository has no visible adoption or security tooling, making abandonment a substantial concern.
36%
Total Score
50
100
71
50
The package has only one release, published in May 2017, with no releases in the last 12 months and no ongoing release cadence. This is strong evidence of abandonment risk.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with an inactive project, though a small package may naturally receive little issue traffic.
The linked repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no community or adoption signal to offset the stale release history.
Composer is used as a build tool, but no security-scanning tooling is present. For a package with an already stale release history, this leaves maintenance and release-quality checks less transparent.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities and offers no compensating security-process evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.