The package has clear licensing and a small runtime footprint. Its last release and repository activity were about 10 years ago, and the linked repository does not identify this package, making continued support uncertain.
38%
Total Score
0
100
69
83
The latest release was about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package intended as a maintained dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
A README is present, while the absent tests and changelog are normal for published package contents and are not treated as gaps here. The very short README offers little consumer documentation, but this is secondary to the maintenance concern.
The linked repository name does not match the package name and its README does not mention the package. Organization backing may explain a subpackage layout, but the package-to-source relationship remains unclear.
Composer is used for build tooling, showing basic project structure, but no security scanning tools are present. This is a hygiene gap that adds little weight compared with the long inactivity period.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.