The package has an MIT license, tests, a stable version, and no install-time scripts. Its tiny user base, absent security tooling, and long-standing lack of maintenance make future fixes and support unlikely.
38%
Total Score
25
75
83
The latest release was in November 2015, with no releases in the last 12 months despite the package being over 11 years old. This is strong evidence of abandonment for a dependency that may need compatibility or security fixes.
There were no commits and no active maintainers in the last three months, consistent with the repository's last push in November 2015. This materially increases abandonment risk.
The package and repository are owned by an individual rather than an organization, so the single registry maintainer does not have broader project backing to compensate for the inactive repository.
The repository has zero stars and forks and only two watchers, so there is little visible community activity or backup support if the package stops working.
Composer is used as the build tool, but no security scanning tools are present. For an old package, the lack of automated security checks is a meaningful maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.