The repository is tiny, with no tests, changelog, or security policy. Its README and Composer dependency are present, but the project shows no recent activity and offers little maintenance evidence.
38%
Total Score
0
33
50
This is the package's only release, published about 14 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a library whose behavior may depend on an external service.
The repository has had no commits and no active maintainers in the last 3 months, consistent with the package's long release gap and leaving no evidence of ongoing maintenance.
No license is declared, and neither the package nor the linked repository contains a license file. This creates a material transparency and adoption risk.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. Given the stale project, this is a modest additional hygiene gap.
The linked repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This compounds the concern created by the project's inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.