The package has had no commits or releases for nearly five years, and its repository has no tests or security scanning. The small dependency surface, MIT declaration, and readable package structure reduce complexity but do not offset the abandonment risk.
42%
Total Score
0
100
75
75
The package has only three releases, all within about two days in November 2021, and none in the last 12 months. This indicates a long-standing release gap and weak evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push nearly five years ago. The inactive source history materially increases abandonment risk.
The package is very small and its artifact matches the repository tree, containing only a README, composer manifest, and one source file. This limits complexity but provides little evidence of mature project structure.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no external indication of active use or review.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tooling is present. The missing scanner is a maintenance and transparency gap, though not severe by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.