The small codebase has clear installation guidance, a declared MIT licence, and no install-time scripts. Its stable release and non-archived repository do not offset the lack of any commits or releases for nearly five years.
42%
Total Score
50
72
83
Only two releases exist, with none in the last 12 months; the latest release was published in December 2021, nearly five years ago. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, alongside a last repository push in December 2021. This is the clearest evidence of current abandonment risk.
The repository has only 4 stars and no forks, indicating limited external adoption or review. Popularity is supporting evidence rather than a verdict, but it adds to the thin-project picture.
Composer is used as the build tool, but no security scanning tooling is configured. The missing scanning is a hygiene gap rather than proof of unsafe code.
The repository is not archived, but its last push was in December 2021. The non-archived status is mildly reassuring, while the stale repository remains consistent with the maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.