The single stable release has had no newer version for 11 years, and the repository has only three stars with no commits in the last three months. Repository tests and package-name alignment help, but all five workflow actions are unpinned and the license metadata conflicts.
15%
Total Score
75
42
Packagist marks the entire package as abandoned and names contributte/uniparser as its replacement. This is a direct warning against taking a new dependency on this release.
The package has only one release, published 11 years ago, with no releases in the last 12 months. That leaves compatibility and maintenance expectations unsupported by release history.
The linked repository is archived, which indicates the source project is no longer intended for normal ongoing maintenance, despite being pushed on December 9, 2025.
The manifest declares BSD-3-Clause, while the repository license file was detected as MIT. The release is licensed, but the conflicting metadata creates avoidable legal ambiguity.
There were no commits and no active maintainers in the last three months. This reinforces the lack of current maintenance capacity, even though the repository was recently pushed.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.