Its minimal artifact includes a README and a GitHub release, while the repository has no tests or security policy. Pinning a package with no license and no updates since December 2021 creates substantial maintenance and legal risk.
38%
Total Score
64
50
The package has only one release, published about 4 years and 10 months ago, with no releases in the last 12 months. This is strong evidence of an abandoned or unmaintained dependency.
Neither the package nor the linked repository declares or contains a detectable license. That leaves the legal terms for using and redistributing the dependency unclear.
The repository has zero stars and zero forks, with one watcher. Popularity is only supporting evidence, but these counters provide little evidence of community validation or support.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is reported. This is a hygiene gap rather than proof of unsafe code.
The repository has no security policy. For a small package this is a transparency gap, though it is less significant than the lack of maintenance and licensing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.