The dependency surface is small, but the available project evidence is too limited to establish ongoing care. The source could not be found, leaving maintenance and provenance unverified.
12%
Total Score
100
17
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk and outweighs the otherwise small dependency surface.
The last release was over eight years ago, with no releases in the past 12 months. That strongly indicates abandonment for a package intended for ongoing use.
The registry reports latest version 0.2 and no stable major version, which is inconsistent with the assessed 2.1.3 release and reduces confidence in the package metadata.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.