Its MIT license and matching repository make its provenance clear. Avoid adding it to new projects because the project shows no meaningful ongoing maintenance.
15%
Total Score
100
43
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.
The package has only one release, published about 11 years ago, with no releases in the last 12 months. That indicates prolonged abandonment rather than a stable, actively maintained project.
The repository is not archived, but it was last pushed about 11 years ago. Its technically available status does not compensate for the long absence of updates.
The package includes a README and has a GitHub release for this version, but the README is only 21 characters and the project has no tests or changelog. The release provides limited transparency for consumers.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but it provides no supporting evidence of active community use.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.