The package includes tests, a README, and only two runtime requirements, which keeps its integration surface small. Its old tooling and absent security policy leave little evidence of current oversight.
38%
Total Score
100
56
75
The latest release was published over 13 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having five historical releases.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository is the package's dedicated source rather than an unrelated or shared repository.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external adoption signal to offset the long inactivity.
Composer is used for builds, but no security-scanning tools are present. For a package this old, the absence of automated security tooling modestly reduces maintenance transparency.
The linked repository is not archived, which is a positive counterweight to the stale release history. However, its last push was over 13 years ago, so it does not show active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.