The package is tiny and has a readable README, with only PHP as a runtime dependency. Its sole release was over five years ago, with no recent commits or security policy, and the linked repository does not identify this package. Pinning it would leave little evidence of ongoing support.
28%
Total Score
0
100
50
75
The package declares no license, contains no license file, and the repository has none either. This creates a concrete legal and reuse barrier with no compensating licensing evidence.
There has been only one release, published over five years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a package developers may need to maintain over time.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old release history, this indicates no observable ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. That raises uncertainty about whether the linked source actually belongs to this release.
The linked repository is not marked archived, which is a small compensating signal. However, its last push was over five years ago, so this status does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.