The package has a clear README, tests, a matching license, and only one runtime dependency. Its tiny audience and lack of a security policy add to the maintenance concern.
43%
Total Score
25
100
78
50
Only one release exists, published about seven years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
There were no commits and no active maintainers in the last three months, consistent with a repository that has seen no recent development for years. This materially raises abandonment risk.
The repository is owned by a user account rather than an organization, so there is no organizational backing signal to offset the single-maintainer context or inactivity.
The repository has one star, no forks, and no watchers, showing very limited external adoption or review. Low popularity is supporting evidence rather than proof of poor quality, but it increases the maintenance concern.
The repository uses Make and Composer, but no security-scanning tooling was detected. The build setup is present, while the missing security checks are a modest transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.