MIT licensing, a small dependency footprint, tests, and a matching repository support straightforward adoption. The missing security policy and scanning leave less transparency for future maintenance.
42%
Total Score
25
100
72
88
The package has had no release in more than 9 years, with all four releases clustered on one day in 2017. This is strong evidence of abandonment despite the stable 1.0.3 version.
There were no commits and no active maintainers in the last 3 months, consistent with the release history showing no release in more than 9 years. This materially increases abandonment risk.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance history. This supports the abandonment concern but is not decisive alone.
The repository has only 3 stars, 0 forks, and 0 watchers, providing little evidence of a broader community that could sustain or repair the package. Popularity is supporting evidence, but it reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. For an old, inactive package, the absence of automated security tooling reduces ongoing transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.