It has a clear MIT license, tests, and a useful README. Its tiny user footprint and lack of security tooling provide little evidence of ongoing support.
38%
Total Score
69
75
The package has had only two releases, both in April 2018, with no releases in more than eight years. This is strong evidence of abandonment risk for a dependency.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but this provides little supporting evidence of active use or community resilience.
Composer build tooling is present, but no security-scanning tools are reported. That is a maintenance and assurance gap, though not severe by itself.
The repository is not archived, which is a modest positive, but it was last pushed in April 2018 and therefore does not offset the prolonged inactivity.
The repository has no security policy. This weakens transparency and gives users no documented route for reporting security issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/http-foundation Version ^4.0 | — | — |
popcorn4dinner/string-format Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.