The project has a clear MIT license, a matching repository, and documented initial-release notes. Its only release is over 23 months old, with no recent commits or active maintainers, so pinning this version carries substantial abandonment risk.
40%
Total Score
25
78
75
This is the only release, published over 23 months ago, with no releases in the last 12 months. That limited history provides little evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the long gap since the only release and increasing abandonment risk.
The repository is owned by an individual user rather than an organization, so there is no provided organization backing to compensate for the thin maintenance record.
The repository has one star and no forks, offering little community evidence or external maintenance support. Popularity is only supporting evidence, so this does not independently determine the score.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap that adds some transparency risk without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.