The package is a small, conventional Composer project with a matching source repository and no install-time scripts. Its last release and repository activity were in 2018, and no license or security policy is provided, making long-term maintenance and legal use uncertain.
36%
Total Score
50
69
75
The package is about 8 years old, has only 5 releases, and has had no releases in the last 12 months; the latest release was in December 2018. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no activity since 2018.
Neither the package metadata nor the collected source files provide a license. That creates a real legal adoption concern, with no licensing evidence to compensate for it.
The artifact has no README, tests, or changelog, although the GitHub release indicator is present and the package appears to distribute a web application component rather than a small utility. The lack of consumer documentation and tests still limits maintainability evidence.
Composer is used as the build tool, which is appropriate for a Packagist package, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than evidence of immediate unfitness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.