It has a README, tests, an MIT license file, and release notes for this version. The repository has no security policy, and its very small audience offers little backup if maintenance is needed.
43%
Total Score
0
72
75
The package has 27 releases, but none in the last 12 months and the latest release was over 8 years ago. This strongly indicates stalled maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with maintenance having stopped for over 8 years.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad maintenance community.
Composer is used for the build, showing basic project tooling, but no security scanning tools are configured. The tooling is adequate but not especially strong for ongoing assurance.
The linked repository is not archived, but its last push was over 8 years ago, so the unarchived status does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mustangostang/spyc Version 0.5.* | — | — |
andersondanilo/cnab_yaml Version ~1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.