The six-file package includes a usable README and MIT licensing, but no tests or security scanning. Its source remains linked and unarchived, though the project has almost no adoption evidence.
32%
Total Score
0
75
50
The package made 20 releases between January and February 2016, but has had no release in about 10 years. That long silence is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the package's roughly 10-year release gap. No newer activity compensates for this.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of community adoption or review. Popularity is supporting evidence, but this reinforces the maintenance concern.
Composer is used as a build tool, but the repository has no security-scanning tooling. This is a modest transparency and maintenance gap rather than a standalone dependency blocker.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters more for an old dependency with no recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.