The small codebase is clearly documented and MIT-licensed, but it has little evidence of ongoing care or security oversight. Expect limited maintenance and few compatibility updates.
38%
Total Score
0
100
75
50
The package has only 3 releases, with none in roughly 10 years; its release cadence stopped after August 2016. That is strong evidence of an aging dependency with little ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating a substantial abandonment risk.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is present. The missing scanning is a modest hygiene concern rather than a standalone adoption blocker.
The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities. This is a secondary transparency gap alongside the stronger maintenance concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.