The package has a clear license, matching repository, and simple Composer dependency profile. It lacks tests and security scanning, so future defects may go unnoticed.
42%
Total Score
25
100
80
50
Only two releases were published, with the latest about 9 years ago and none in the last 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with its last push being about 9 years ago. This is a substantial abandonment concern.
There has been no issue or pull request activity in the last month, with one issue still open. This provides no evidence of current maintenance or responsiveness.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The small package scope limits the impact, but this remains a transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.