The small package is clearly identified and has a matching source repository. Its license texts conflict, and maintenance has been inactive for nearly 11 years, making this release a liability for new dependencies.
38%
Total Score
50
100
64
88
Only three releases were published, all in late 2015, with no release in nearly 11 years. This strongly indicates abandonment despite the short early release interval.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly 11-year release gap and providing no evidence of current maintenance.
The artifact contains a license file, but it is detected as GPL-2.0 while the manifest declares MIT. The package is licensed, yet the mismatch requires resolving which terms apply.
A README is present, and the absence of tests and a changelog is normal for a published artifact; the repository also provides neither, so this is only a minor transparency limitation.
Composer is used as the build tool, but no security scanning tools are present. This is a modest hygiene gap, not a substitute for the much stronger maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.