The package is small, focused, documented, and has a direct source match with minimal runtime dependencies. Treat it as legacy code and avoid introducing it where ongoing fixes or active support are required.
8%
Total Score
50
100
50
88
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry explicitly signals that maintenance has ended.
The package has only three releases, all concentrated in 2015, and none in the last 12 months; its latest release is more than 11 years old. This strongly indicates abandonment rather than a merely slow cadence.
There were zero commits and zero active maintainers in the last three months, consistent with the repository being abandoned. This reinforces the maintenance risk already shown by the archive and deprecation signals.
The linked repository is archived and was last pushed in July 2015, so it is no longer maintained through its source project. This independently makes the release unfit for dependencies requiring ongoing support.
The repository has zero stars and forks and one watcher, offering little supporting evidence of adoption. Popularity is only secondary evidence, so this does not drive the verdict alone.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.