The codebase offers little consumer guidance or visible quality checking. Stable versioning and organization backing provide some context, but the package has seen no updates for years and remains a risky dependency.
38%
Total Score
83
100
72
83
Only two releases appeared, both in February 2018, with no releases in the last eight years. This is strong evidence of abandonment risk despite the package not being deprecated.
The artifact and repository contain no README, tests, or changelog. Missing tests and changelogs can be normal for published artifacts, but the absent README reduces transparency for a library consumers must integrate.
The repository has no open issues or pull requests and no activity in the last month. Combined with the old release history, this supports a conclusion of inactivity rather than active maintenance.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community use or review. Popularity is only supporting evidence, but its absence adds to the limited maturity signals here.
Composer is used as the build tool, providing basic project tooling. No security scanning tools were detected, leaving a minor process gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.