The package is small, clearly identified, licensed, and has no install-time scripts. Its license texts disagree, and the repository has no security policy or scanning; the long inactivity makes continued support uncertain.
45%
Total Score
25
75
75
The latest release was in December 2021, with no releases in the last 12 months. That long release gap is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the multi-year release gap and offering no evidence of ongoing maintenance.
The package declares GPL-2.0-or-later, while the detected LICENSE file identifies GPL-3.0. A license is present, but the mismatch should be resolved before adoption.
Only one registry account can publish the package. This creates a thin publishing base, although the linked repository is owned by the same individual.
Composer is used for the build, but no security-scanning tools are configured. The missing scanning is a modest transparency and maintenance gap for a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.