The stable release is MIT-licensed and installs without lifecycle scripts, which reduces immediate adoption friction. Maintenance evidence is weak: the project has been inactive for about three years, has no tests or security policy, and the linked repository does not match the package name.
42%
Total Score
0
69
83
The package has had five releases, but none in about three years and all releases were clustered on the first day, indicating little ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The linked repository name does not match the package name, and no README mention was available, so package ownership is less transparent than expected.
The repository has zero stars and forks and only one watcher; popularity is supporting evidence rather than a verdict, but this provides no meaningful community backing to offset inactivity.
Composer is used for builds, but no security-scanning tooling was detected, providing less automated protection against dependency issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.