The codebase is tiny and easy to inspect, with a clear MIT declaration and no install-time scripts. Its limited project safeguards provide little evidence that future compatibility or security issues will be handled.
38%
Total Score
0
100
72
83
The package has had only one release, published about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, consistent with the repository having been inactive since June 2016.
The repository has 4 stars and no forks, indicating limited adoption and little visible community support. Popularity is supporting evidence rather than the main reason for the low score.
Composer is used for the build, but no security-scanning tooling is present. For a small library this is a modest transparency and maintenance gap.
The linked repository is not archived, but it was last pushed about 10 years ago. The non-archived status does not compensate for the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.