The package is small and easy to inspect, with a clear README and no install-time scripts. Its single release and repository activity from December 2021 leave substantial abandonment risk, with no tests or security policy to support ongoing maintenance.
42%
Total Score
64
75
The package has only one release, published about 4 years and 9 months ago, with no releases in the last 12 months. This is strong evidence of limited maintenance for a dependency.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these very low adoption signals provide little evidence of a sustained user or contributor base.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tooling is present. This is a minor hygiene gap rather than evidence that the release is unsafe.
The repository is not archived, which avoids an explicit abandonment marker, but it was last pushed about 4 years and 9 months ago. That stale activity reinforces the maintenance concern shown by the release history.
The repository has no security policy. For a small, old package this is a transparency gap, though it is less significant than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.