It has a clear MIT license, a focused artifact, and repository tests. The lack of security scanning and a security policy leaves less assurance for ongoing maintenance.
57%
Total Score
50
100
75
83
Only two releases were published, with the latest in January 2015 and none in the last 12 months. That long release gap is a meaningful abandonment concern for a dependency, despite the package being mature and stable.
The repository is owned by a user account rather than an organization, so there is no visible organizational backing to compensate for the single-person project context.
There are no open issues or pull requests and no issue or pull-request activity in the last month. Combined with the old release and push dates, this supports a conclusion of inactive maintenance.
Composer is used for the build, but no security scanning tool is configured. For a small package this is a minor transparency gap rather than a severe risk.
The linked repository is not archived, which is a compensating sign, but it was last pushed nearly eight years ago and does not overcome the stale release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.