Its stable 1.0.1 package has no runtime dependencies, and the repository is neither archived nor mismatched. The lack of maintenance since 2015 makes it a liability for a new project.
36%
Total Score
0
100
67
75
The package has had only two releases, both in August 2015, with no release in more than 11 years. That strongly suggests the package is no longer maintained.
There were zero commits and zero active maintainers in the last three months, consistent with the absence of releases since 2015 and indicating severe abandonment risk.
Composer is used for builds, but no security-scanning tooling is present. This is a hygiene gap, though the package's much older concern is its lack of maintenance.
The linked repository is not archived, which is a positive sign, although its last push was still in August 2015 and does not show current maintenance.
The repository has no security policy. That reduces transparency for reporting vulnerabilities, but it is secondary to the clear maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.