The package includes tests, release notes, and a matching repository, but it remains an alpha release with no commits for over two years. The license declaration also conflicts with the detected MIT license, and the repository lacks a security policy.
12%
Total Score
0
43
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on this release.
Only two releases were published, both within 12 days, followed by no release in over two years. This provides little evidence of sustained maintenance.
The repository had zero commits and zero active maintainers in the last three months, consistent with abandonment rather than active support.
The linked repository is archived, and its last push was over two years ago. Archived source indicates the project is no longer maintained.
A license file is present, but the manifest declares BSD while the artifact license file is detected as MIT. The mismatch reduces licensing clarity even though the release is licensed.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.