Risky to adopt for a new project: the package has had no release or repository activity for about five years and contains only two files. It is not deprecated and has a declared MIT license, but its very small footprint and lack of tests or security process leave little evidence of ongoing maintenance.
42%
Total Score
0
100
64
75
There has been only one release, published about five years and seven months ago, with no releases in the last 12 months. This is strong evidence of an unmaintained package.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since its only release. No newer activity is provided to offset the abandonment concern.
Both the published artifact and repository contain only composer.json and one PHP source file. This may be a deliberately small middleware package, but the minimal tree provides limited transparency about its maintenance and validation.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. Missing tests and changelog can be normal for a tiny published artifact, but the absent README makes integration harder and leaves little consumer-facing documentation.
The repository uses Composer, but no security scanning tools are reported. The simple package structure limits the significance of this gap, though it leaves maintenance safeguards unverified.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.