Risky to adopt without careful review: the package has had no release or commit activity for about three years, and its README still lacks a usable example. It is licensed, stable, not deprecated or archived, and has a small dependency surface, but maintenance appears abandoned.
48%
Total Score
0
100
72
75
The package has 39 releases since 2017, but none in the last three years and its latest release was in November 2022. That long gap materially raises abandonment risk despite the earlier release history.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release-history gap. This is strong evidence that current maintenance capacity is absent.
A README is present, but it is only 175 characters and says the usage example will be added later. The absence of tests and a changelog in the published artifact is normal packaging practice, so the concern is limited to poor consumer documentation.
The repository has zero stars and forks and only one watcher. Low popularity is supporting evidence of limited adoption, not a decisive health problem by itself.
Composer is used as the build tool, but no security-scanning tooling is present. For this very small package that is a transparency gap, though it is less significant than the demonstrated maintenance inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.