Organization backing and a matching, documented repository provide useful traceability. The package has no recent release or commit activity, and its GPL-3.0 declaration conflicts with the MIT license file.
60%
Total Score
67
79
50
A GPL-3.0 license is declared and a license file is present, so this is not an absence of licensing. However, the artifact license file is detected as MIT, creating a material license mismatch that should be resolved before adoption.
The package has five releases over roughly nine years, but none in the last 12 months; the latest release was published about 15 months ago. This indicates materially slowed maintenance.
There were no commits and no active maintainers in the last three months, consistent with the release-history slowdown and increasing abandonment risk.
No issues or pull requests were opened or merged in the last month, and none remain open. Combined with zero recent commits, this provides little evidence of active project maintenance.
The repository uses Composer, which supports a conventional build process, but no security scanning tools were detected. That is a maintenance and transparency gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.