The linked project is backed by an organization and includes tests, a changelog, and a detected BSD-3-Clause license. Its repository is not archived, but recent commit and issue activity is absent, so future maintenance is uncertain.
62%
Total Score
67
81
50
The package has had no release in more than 10 years, with zero releases in the last 12 months. This is strong evidence of stagnation for a dependency that may need compatibility or security updates.
There were zero commits and zero active maintainers in the last three months. Combined with the old registry release, this raises a meaningful risk of abandonment.
There were no new or closed issues or pull requests in the last month, with only three open issues and one open pull request. This suggests little active maintenance or community response.
Composer build tooling is present, but no security-scanning tool was detected. This is a minor transparency gap rather than a severe concern because the project has a linked repository and established packaging structure.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. This matters more for a server-side remoting library, which may expose network-facing functionality.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.