The focused codebase includes tests and has only one runtime dependency, which keeps adoption straightforward. Its long inactivity and very small user base make future fixes and compatibility work uncertain.
42%
Total Score
50
100
72
88
The package has made no releases in the last 12 months, and its latest release was in May 2015 despite being over 11 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release silence. No provided signal shows current maintenance capacity.
The repository name does not exactly match the package name, but it is closely related and belongs to the same shouldbee organization. The available data does not show a README mention, so this remains a minor identity-transparency concern rather than a severe mismatch.
The repository has 0 stars and only 1 fork, so there is little visible community support to compensate for the inactive maintainer activity. Popularity is supporting evidence rather than decisive on its own.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest transparency gap, not a primary reason to reject this small package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.