The package has clear MIT licensing, repository tests, and minimal runtime dependencies. Its sole release is nearly 12 years old, with no releases or commits in the measured recent periods, making future maintenance uncertain.
42%
Total Score
50
100
71
50
There has been only one release, published nearly 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the repository remaining available.
The repository recorded no commits and no active maintainers in the last three months. Its last push was in 2023, which does not demonstrate current maintenance capacity.
The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external evidence of maturity or community support.
Composer is used as the build tool, but no security scanning tooling is present. The missing scanning is a modest hygiene gap rather than a standalone adoption blocker.
The repository has no security policy. This is a transparency and response-process gap, although it is secondary to the much older release and inactive commit history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.