Usable with caveats: this is a small, clearly packaged utility with a license, documentation, and no install scripts, but it has had no release or repository activity for nearly 8 years. Depend on it only if its unchanged API meets your needs and you can accept that maintenance appears dormant.
56%
Total Score
75
100
81
83
The package has made no release in nearly 8 years, despite 12 historical releases; that is a substantial maintenance and abandonment concern for a dependency, although the stable 1.0.9 version may suit a small, mature utility.
The repository recorded zero commits and zero active maintainers in the last 3 months, and the last push was nearly 8 years ago; this is the main risk because fixes and compatibility updates may not arrive.
The repository uses Composer, but no security-scanning tooling is present. For this very small package that is a modest hygiene gap, not evidence that it is unsafe to depend on.
The linked repository is not marked archived, so it remains technically open to maintenance. However, its last push was nearly 8 years ago, consistent with the separate evidence of dormancy.
No security policy is provided. This limits the documented response path for vulnerabilities, though the package's small scope and lack of workflow automation reduce the practical significance of this gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.