The project is permissively licensed and has no install-time scripts. Its repository remains available and documents the package, but it has no security policy or security scanning, leaving limited evidence of ongoing care.
43%
Total Score
25
71
83
The last release was in December 2019, with no releases in the past 12 months. That long period without updates is strong evidence of abandonment risk for a package that may need compatibility fixes.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's extended release gap and indicating no current maintenance activity.
The registry lists one maintainer. The linked project is user-owned rather than organization-backed, so the narrow publishing base provides limited resilience if that maintainer stops maintaining it.
The repository has 1 star, 1 fork, and 1 watcher, providing little evidence of a broad user or contributor community to help sustain the project.
Composer build tooling is present, which supports a conventional package workflow, but no security scanning tools are configured. The missing scanning weakens ongoing supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.