The package has one registry maintainer and no security policy, limiting visible ownership and response planning. Its substantial source tree and Composer build are useful, but the very brief README leaves little guidance for consumers.
32%
Total Score
25
60
50
The package is over 8 years old, has only 3 releases, and has had no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, with its last push in January 2018. This indicates maintenance has effectively stopped.
Neither the package nor the linked repository declares or contains a recognized license. That creates a real adoption and redistribution concern.
Only one registry account has publish access. With no organization backing shown, this leaves a thin publishing and continuity base.
The repository name does not match the package name and its README does not mention the package. The link may be incorrect or the package may be piggy-backing on unrelated source.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.