Tests, documentation, and a matching MIT license make the code easier to evaluate. The small dependency surface and organization-backed repository help, but do not offset the long-standing lack of maintenance.
38%
Total Score
67
100
81
50
The package has had only 3 releases, with none in the last 12 months; its latest release was in March 2014, about 12 years ago. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, while its last push was in March 2014. This is the strongest evidence that the project is no longer actively maintained.
There is only 1 open issue and no issues or pull requests were opened or closed in the last month. Together with the old release history, this supports a concern about inactivity.
Composer build tooling is present, but no security scanning tooling was detected. The missing scanning is a modest transparency and maintenance gap, not a standalone adoption blocker.
The repository has no security policy. For an old package this leaves vulnerability reporting and response expectations unclear, adding to its maintenance risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.