The MIT license, small runtime dependency surface, and clear package-to-repository match support adoption. The project has had no registry releases or repository commits since 2019, leaving maintenance and compatibility risks.
55%
Total Score
63
100
81
83
One registry maintainer is consistent with a small user-owned project, but it leaves little visible publishing redundancy when combined with the long period of inactivity.
The package is about 7 years old but has had no releases in the last 12 months; its eight releases were concentrated in November 2018, which points to prolonged inactivity.
There were zero commits and zero active maintainers in the last 3 months, reinforcing that ongoing fixes and compatibility work are unlikely.
There was no issue or pull-request activity in the last month and one issue remains open, providing no evidence of active support.
The repository uses Composer, but no security-scanning tool is present. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.