The MIT license, README, and release notes provide basic transparency for consumers. No security policy and no security scanning reduce assurance further for a package this old.
12%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement given. This is a direct warning against taking a new dependency on it.
Only two releases were published, both in February 2015, with no release in roughly 11 years. This strongly indicates abandonment rather than an actively maintained stable project.
The repository had zero commits and zero active maintainers in the last three months, consistent with its long period without updates.
The linked repository is archived and was last pushed about 11 years ago, so active maintenance and issue response should not be expected.
Composer build tooling is present, but no security-scanning tooling was detected. This is a minor assurance gap and does not offset the maintenance concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.