The package is small, clearly licensed, tested, and has no install-time scripts. Its age, inactive repository, and pre-1.0 version make ongoing compatibility and maintenance unlikely.
38%
Total Score
25
64
83
The package has only three releases, all published within minutes on September 6, 2019, and none in the last 12 months. This is strong evidence of abandonment for a dependency released over seven years ago.
There were zero commits and zero active maintainers in the last three months. For a package last updated in 2019, this confirms that maintenance has stopped rather than merely slowed.
Only one registry account has publish access. The repository is organization-owned, which provides some backing context, but no activity signal shows that this backing is actively maintaining the package.
The repository uses Composer, but it has no security-scanning tools. This is a modest transparency and maintenance gap, though the package's much older inactivity is the larger concern.
The repository is not archived, so it remains available for maintenance. However, its last push was in September 2019, which does not offset the separate evidence of inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.