MIT licensing, included tests, and a very small runtime dependency footprint make the package straightforward to inspect and integrate. The missing security tooling provides little additional assurance if the project ever resumes development.
38%
Total Score
50
75
100
The package has only one release, published nearly 7 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, despite the package not being deprecated.
The repository has had no commits and no active maintainers in the last 3 months, consistent with the nearly 7-year gap since its last push. This materially weakens confidence in ongoing maintenance.
The repository uses Make and Composer, which supports reproducible project tasks, but it reports no security scanning tools. That leaves a modest transparency and maintenance gap.
Version 0.1 is not a stable major release, and the project never progressed beyond its initial published version. The prerelease flag is false, but the unchanged early version adds maturity concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.