Risky to adopt: the package is well-scaffolded and licensed, but its last release and repository update were in April 2018, with no releases in the past year. It appears effectively unmaintained despite having tests and documentation.
45%
Total Score
100
75
83
The package has only two releases, both from 2018, and none in the last 12 months; this is strong evidence that maintenance has stopped for a dependency last updated about eight years ago.
Composer is used as a build tool, but no security-scanning tooling is reported; this is a modest process gap rather than a standalone severe risk.
The repository is not formally archived, but its last push was on April 3, 2018, which does not compensate for the similarly stale release history.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap, though the package's long inactivity is the more significant concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.