The MIT license and included tests make the package straightforward to inspect and integrate. Its stable artifact is small, but there is little evidence that future fixes or compatibility updates will arrive.
12%
Total Score
0
42
100
Packagist marks the entire package as abandoned, with no replacement provided. Package-level abandonment is a severe dependency-lifecycle risk.
The latest release was published in September 2016, and there were no releases in the last 12 months. A package with roughly ten years without a release has substantial compatibility and abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms the absence of current maintenance rather than merely a slow release cadence.
The linked source repository is archived, which indicates the project is no longer intended for active maintenance. This strongly outweighs the organization backing and otherwise usable package contents.
The repository name does not match the package name and its README does not mention the package, creating uncertainty about whether the linked repository directly represents this package. Organization ownership and the matching file tree partly reduce that concern, so this is caution rather than danger.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.