The README, tests, and exact GitHub release make the package easy to inspect. Its tiny ecosystem footprint and old tooling leave little evidence of ongoing support; choose a maintained URI library instead.
42%
Total Score
50
100
63
83
The package has made only two releases, both in August 2014, with no releases in the last 12 months. This long period without a new release is strong evidence of abandonment risk.
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not benefit from visible organizational backing.
The repository has only 3 stars and no forks, providing little supporting evidence of broad adoption or an active user community. Popularity is secondary, but this reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tool is configured. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository is not archived, which is a meaningful positive, but it was last pushed in October 2014 and therefore does not offset the broader evidence of inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.