Tests, a usable README, and a small dependency surface improve transparency. The missing security policy and absent security scanning provide less assurance for a package this old.
35%
Total Score
50
100
72
83
The latest release was published in June 2013, with no releases in the last 12 months; this is strong evidence of abandonment despite a previously regular release cadence.
There were no commits and no active maintainers in the last three months, consistent with the package having been inactive since 2013.
The repository has only 2 stars and no forks, offering little evidence of a broad community that could compensate for the inactive maintainer.
Composer is used as a build tool, but no security scanning tooling is configured; this is a modest transparency and assurance gap.
The linked repository is not archived, but its last push was in June 2013; the non-archived status does not compensate for the stale activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.