Tests and licensing provide a usable baseline, but the project offers little evidence of ongoing care. Fixes would depend on a lone maintainer returning after years of inactivity.
12%
Total Score
25
60
50
Packagist marks the entire package as abandoned, with no replacement given. This is a direct warning against taking a new dependency on the package.
The package has only one release, published about 11 years ago, with no releases in the last 12 months. That leaves no evidence of maintained release delivery.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with a project that has been inactive for years. The non-archived status does not compensate for the absent activity.
One issue and one pull request remain open, while neither received activity in the last month. This suggests maintenance requests are not being handled promptly.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it is secondary to the abandonment evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.