Usable with caveats: this is a small, stable MIT API package with a simple dependency profile and no deprecated or dangerous installation behavior. However, it has had no release or repository activity since January 2023, with no tests, README, changelog, or security policy.
55%
Total Score
50
100
81
90
The artifact has no README, tests, or changelog, while the repository also has no tests or changelog. The small 13-file interface-focused package makes missing tests less severe, but the absent README still reduces consumer transparency.
The repository is owned by an individual rather than an organization, so the short registry maintainer context offers limited evidence of institutional maintenance capacity.
Only two releases exist, and the latest was in January 2023—about 3 years and 8 months before collection—with no releases in the last 12 months. That materially raises abandonment and compatibility risk.
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the last release and indicating weak evidence of ongoing maintenance.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is present. For a small library this is a hygiene gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.