The package is small and clearly documented, with tests and no install-time scripts. Its sole maintainer shows no recent activity, and the registry marks the package abandoned; the missing license further limits transparency.
15%
Total Score
0
50
100
Packagist marks the entire package as abandoned, with no distinct replacement provided. This is a severe adoption concern because the registry itself signals that ongoing support should not be expected.
The package has had only 3 releases, all in December 2017, and none in the last 12 months. This long release gap strongly indicates abandonment for a dependency consumers may need to maintain.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring in December 2017. There is no observed recent maintenance capacity.
No declared license, license file, or repository license file was detected. That leaves the release without clear permission for downstream use and is a genuine transparency concern.
The repository is not formally archived, which avoids one severe status signal, but its last push was in December 2017 and does not offset the abandoned registry status or absent recent activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.