Risky to adopt: the package has had no release or repository commits for over two years, with no active maintainers visible and almost no community uptake. It is not deprecated or archived and has a valid MIT declaration, but maintenance appears abandoned.
42%
Total Score
0
69
88
The package is about 825 days old but has had no releases in the last 12 months; its seven releases were concentrated in roughly one month, leaving no evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent registry releases and indicating substantial abandonment risk.
The repository has zero stars and forks and only one watcher, so there is little visible community attention to compensate for the lack of recent maintenance.
Composer is used as the build tool, but no security scanning tooling is present. This is a modest transparency gap rather than evidence that the release is unsafe on its own.
The linked repository is not archived, although its last push was over two years ago; the active archive status does not offset the stronger inactivity evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.