The package has substantial unit and integration tests, organization backing, and no install-time scripts. Its repository is not archived and the release is stable, but the absence of security scanning leaves an additional maintenance gap.
40%
Total Score
50
100
79
75
The package has had no release in over 10 years: its latest release was June 2016, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite its seven historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long period without releases and leaving little evidence of ongoing maintenance.
No declared license or license file was found in the package or repository, creating a concrete legal and adoption risk for downstream users.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities. This compounds the risks of an inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.1 | — | — |
justinrainbow/json-schema Version ~1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.