The narrow dependency set, included tests, and release notes make the package straightforward to evaluate. Its maintenance has effectively stopped, with no recent commits or releases, and the repository lacks a security policy.
42%
Total Score
25
100
60
75
There were no commits and no active maintainers in the last 3 months. Combined with the repository's 2015 last push, this indicates the project is effectively unmaintained.
The latest release was published in September 2015, with zero releases in the last 12 months; this is strong evidence of abandonment for a library that may need compatibility updates.
There has been no issue or pull-request activity in the last month, while two issues remain open. This provides additional evidence of low maintenance responsiveness.
The project uses Composer for its build setup, but no security-scanning tools are present. The missing scanning is a modest transparency and maintenance gap, not proof of a defect.
The repository is not archived, so it remains available for inspection and potential maintenance. However, its last push was in November 2015, which reinforces the inactivity shown elsewhere.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.