The small codebase is easy to inspect, with an MIT license, README, and no install-time scripts. Its single maintainer and minimal testing and security tooling leave little evidence of ongoing support.
43%
Total Score
0
100
75
75
The latest release was published in December 2016, and there have been no releases in nearly ten years. This strongly raises abandonment risk despite the package having two historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This is strong evidence that maintenance has stopped.
The repository has 1 star and no forks, providing little community evidence or backup around this dependency. Popularity is only supporting evidence, but it does not offset the inactivity.
Composer is used for builds, which is appropriate, but no security-scanning tooling is present. The missing scanning is a modest hygiene gap rather than a standalone adoption blocker.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a secondary concern for an otherwise very small, inactive package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.