The package is minimal and has no install-time scripts, but provides no tests or security policy. Its source repository does not identify the package in its README, weakening confidence that it is the authoritative project.
42%
Total Score
67
75
There has been only one release, published nearly four years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the package may be intentionally stable.
The repository name does not match the package name and its README does not mention the package. This weakens confidence that the linked repository is the authoritative source rather than merely a related project.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these counters provide no visible community backing.
Composer is used as a build tool, which supports ordinary package publication, but no security-scanning tools are present. This is a modest transparency and maintenance gap.
The repository is not archived, but it has not been pushed since the initial release nearly four years ago. The lack of recent activity still points to weak maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.