The repository is small, with five stars, one fork, no security policy, and no automated security scanning. Its BSD-3-Clause license, matching package and repository names, clear README, and lack of install scripts improve transparency and reduce operational risk.
38%
Total Score
0
71
75
The package has only two releases, both published in 2014, with no releases in the last 12 months. More than 12 years without a release is strong evidence of abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the past 3 months. This reinforces the long release gap and leaves little evidence of ongoing maintenance.
The repository has 5 stars, 1 fork, and 1 watcher, providing little evidence of a broad support community. Low popularity is supporting evidence rather than a verdict, but it offers limited compensation for inactivity.
Composer build tooling is present, but the repository reports no security-scanning tools. This is a maintenance and transparency gap, though it is less serious than the inactivity.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, although it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.