The package has a clear README, tests, MIT licensing, and no install-time scripts. Its very old release history and absent recent commit activity make abandonment the main concern, while the small codebase limits maintenance demands.
45%
Total Score
0
100
75
75
Only one release exists, published over 10 years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance, despite the package being mature and stable.
There were no commits or active maintainers in the last three months. Combined with the last push being over five years ago, this is strong evidence of inactive maintenance.
The repository uses Composer and Phing build tooling, showing a reproducible project structure, but it has no detected security scanning.
The linked repository is not archived, which preserves a path for future maintenance. Its last push was in January 2021, however, consistent with the stale activity seen elsewhere.
The repository has no security policy. This is a transparency gap, though the package is small and the absence is less significant than its prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.