The MIT license and matching repository make its origin and reuse terms clear. However, the package has had no release or commit activity since June 2019, with no tests or security scanning to support ongoing maintenance. Treat it as an aging dependency and avoid new adoption unless you can maintain it yourself.
42%
Total Score
50
58
50
This package has only one release, published in June 2019, and none in the following seven years. That strongly indicates abandonment rather than an actively maintained release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since June 2019.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community adoption or external maintenance. Popularity is only supporting evidence, so this reinforces rather than determines the concern.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is less significant than the long inactivity period.
The repository is not archived, which leaves the project technically maintainable, but its last push was in June 2019 and does not offset the absence of recent commits.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.