The package is a very small, lightly governed project with no security policy or automated security scanning. Its README is useful and the repository still matches the package, but the release is not a sound choice for a new dependency.
12%
Total Score
25
50
50
No license is declared, and neither the package nor repository contains a license file. This leaves the legal terms for using the dependency unclear.
Packagist marks the entire package as abandoned. Package-level deprecation is a severe adoption risk even though a replacement is not meaningfully identified.
Only two releases were published, both in November 2017, with no releases in the last 12 months. The nearly nine-year release gap is strong evidence of abandonment.
The repository had zero commits and zero active maintainers in the last three months. Combined with the old last push, this indicates sustained abandonment rather than a short quiet period.
Only one registry account has publish access. The single maintainer is consistent with the user-owned project backing, but it provides little resilience if that maintainer stops maintaining it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.