Risky to adopt for new projects: the package has seen no release or repository activity for nearly eight years. It is clearly licensed, documented, and not deprecated or archived, but its maintenance appears effectively abandoned.
42%
Total Score
0
100
71
50
The latest release was published nearly eight years ago, with no releases in the last 12 months. That is a substantial maintenance concern for a development-tool configuration package.
The repository has had no commits and no active maintainers in the last three months, consistent with the long release gap and indicating very low maintenance capacity.
The repository reports zero stars, forks, and watchers, offering no community activity to compensate for the lack of recent maintainer activity.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling is present. This is a minor transparency gap rather than the main adoption risk.
The repository has no security policy. For this small package that is a limited concern, but it provides no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.