The tiny sample layout and matching repository make its purpose clear, and it has no install-time scripts. The missing license still makes adoption difficult for a project that must redistribute or audit it.
35%
Total Score
50
58
100
This package has only one release, published about 12 years ago, with no releases in the last 12 months. That strongly indicates abandonment despite the repository remaining available.
The repository has had no commits and no active maintainers in the last three months, consistent with the lack of releases for about 12 years. The organization backing does not offset the absence of observed maintenance.
There is no declared license, detected license, or license file in the package or repository. That creates a real adoption and redistribution barrier with no compensating licensing evidence.
Composer is used for the build, which is appropriate, but no security scanning tools are configured. For this small sample package this is a secondary hygiene gap rather than the primary risk.
The assessed version is still 0.0.1-alpha, and every recent release is a prerelease. This signals an immature, unfinished release line.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.