Usable with caveats: the package is clearly licensed, tested, documented, and has minimal dependencies, but its only registry releases ended about 9 years ago. The repository is not archived and was pushed recently, yet it shows no commits or active maintainers in the last 3 months.
60%
Total Score
67
100
83
83
Although the package has six releases and a reasonable early cadence, its latest release was about 9 years ago and there were no releases in the last 12 months. This is a meaningful maintenance concern for a library dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is the strongest evidence of currently weak maintenance, even though the repository is not archived.
There are no open issues and one open pull request, but no issues or pull requests were closed in the last month, indicating limited current project throughput.
The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little external evidence of maturity or community support.
Composer build tooling is present, but no security scanning tools were detected. For this small, older PHP library this is a transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.