The package includes tests, a substantial README, release notes, and matching MIT licenses, with clear organization backing. Its small user base, absent security policy, and lack of recent repository activity reduce confidence in long-term maintenance.
55%
Total Score
50
100
78
75
The repository had zero commits and zero active maintainers in the last three months, reinforcing the broader evidence that maintenance has stalled.
The latest release was almost three years ago, with no releases in the last 12 months; the 14-release history shows earlier activity but not current maintenance.
There are no open issues or pull requests and no activity in the last month; this is consistent with a quiet project but does not by itself prove abandonment.
Six stars and four forks show a small community footprint. Popularity is supporting evidence rather than a verdict, but this provides little external maintenance signal.
Composer is used for builds, but no security scanning tooling was detected, leaving a repository hygiene gap for a library with runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^2.0 | — | — |
sdpmlab/anser-action Version ^0.3.0 | — | — |
pingyi/json-serializer Version ^0.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.