The declared license and lack of install-time scripts are clear. The package has seen no releases or repository commits for nearly five years, and the linked repository does not identify or mention it; its tiny README and absent security policy add transparency concerns.
38%
Total Score
0
69
75
Only three releases were published, all clustered in October 2021, with none in the last 12 months; this indicates prolonged maintenance inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly five-year release gap and raising abandonment risk.
The package includes a very short 15-character README and no tests or changelog. Missing tests and changelog are normal in published artifacts, but the minimal README offers little consumer documentation.
The repository name does not match the package name and its README does not mention the package, leaving the package-to-source relationship poorly substantiated.
Composer build tooling is present, but no security-scanning tooling was detected; this is a modest process gap alongside the stronger maintenance concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.