The package is clearly licensed and documented, with a small dependency surface and matching source repository. Its maintenance has effectively stopped, and the repository has little adoption or security process.
38%
Total Score
50
100
72
88
The package has had no release in nearly 10 years, with all four releases concentrated in January 2016. This is strong evidence of abandonment for a dependency that may need compatibility fixes.
There were zero commits and zero active maintainers in the last three months, consistent with the release history showing that maintenance stopped years ago.
There is no recent issue or pull-request activity, while one pull request remains open; this offers no evidence of active maintenance.
The repository has only 2 stars, 6 forks, and 1 watcher, providing little evidence of a broad user or maintainer community to compensate for inactivity.
The repository uses Composer, but no security scanning tools are present. For this small, old plugin that is a transparency and hygiene gap rather than standalone evidence of danger.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.