The README is clear and the package has no runtime dependencies, while organization backing and a matching repository improve transparency. No security policy and very limited project visibility add smaller concerns.
45%
Total Score
75
100
78
75
This package has only one release, published nearly 11 years ago, with no releases in the last 12 months. That is strong evidence of an inactive or abandoned dependency.
The repository had zero commits and zero active maintainers in the last three months. Combined with the old last push, this indicates little current maintenance capacity.
The repository has only 2 stars and 1 fork. This is weak supporting evidence and makes community reinforcement less likely, but popularity alone is not a health verdict.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest transparency gap.
The linked repository is not archived, although its last push was about four years and nine months ago, so the active status does not establish current maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.