The package is small, stable, and has only one runtime dependency. Its repository lacks security scanning and a security policy, providing little evidence of ongoing oversight.
32%
Total Score
0
100
64
75
The package has had no release in more than seven years: its latest release was in April 2019, with no releases in the last 12 months. This is strong evidence of abandonment despite the short early release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The repository is not archived, but that does not compensate for the absence of recent work.
No license is declared, and neither the package nor the linked repository contains a recognized license file. This creates a material adoption and redistribution risk.
Composer is used for the build, but no security-scanning tooling is present. The build setup is a small positive, while the missing scanning is a modest transparency gap.
The linked repository is not archived, so it remains formally available. Its last push was in May 2019, meaning the unarchived status is not evidence of active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.