The package is small and focused, with a clear README, tests, MIT licensing, and minimal dependencies. Its source remains available and unarchived, but ongoing maintenance evidence is weak.
46%
Total Score
25
100
75
50
The package has had only three releases, all clustered in September 2017, with no release in nearly nine years. This is strong evidence of abandonment risk for a dependency.
The repository recorded no commits or active maintainers in the last three months, and its last push was in July 2019. The long-standing lack of activity materially lowers confidence in ongoing maintenance.
One individual account has registry publishing access, and the project is user-owned rather than organization-backed. This is a thin maintenance base, especially alongside the stale release and repository activity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance-process gap, not a severe risk on its own.
The repository has no security policy. For a small PHP library this is a hygiene gap, though it is less significant than the evidence of prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.