MIT licensing, a minimal dependency footprint, and a readable four-file package make the code easy to evaluate. It has no tests or security tooling, and shows no demonstrated maintenance beyond its 2018 release.
42%
Total Score
50
100
64
83
This is the package's only release, published over eight years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the package is not deprecated.
The repository is owned by an individual user rather than an organization, and the registry namespace does not show broader project backing. Combined with the stale activity, this leaves limited visible maintenance capacity.
The repository has 0 stars, 1 fork, and 1 watcher. Popularity is only supporting evidence, but these very low figures provide little evidence of community support for an already inactive project.
Composer is used as a build tool, but no security scanning tools are present. For a small package this is a hygiene gap rather than a severe risk, though it weakens ongoing assurance.
The repository is not marked archived, but it was last pushed over eight years ago, matching the stale registry history. Its status provides no evidence of active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.