The package is small, clearly licensed, and has a usable README. However, the linked project shows no recent commit activity and no tests or security policy, leaving little evidence of ongoing support.
15%
Total Score
50
100
50
67
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the release.
The package is nearly 10 years old and has had only three releases, with none in the last 12 months; its latest release was in December 2016. This strongly indicates abandonment.
The artifact contains PHP Composer plugin files, while the linked repository tree is a JavaScript project with unrelated build files. This weakens confidence that the source repository transparently represents the published package.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push timestamp does not show ongoing development activity.
The linked repository has no security policy. For an old, abandoned package this adds to the lack of maintenance and vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.