The package has a very small footprint and limited project safeguards, which makes long-term support harder to assess. Its stable version and minimal runtime dependency help, but the maintenance picture remains weak.
35%
Total Score
33
100
61
67
The latest release was published on May 31, 2021, and there have been no releases in the last 12 months. A five-year release gap is strong evidence of abandonment risk, despite 14 releases during the initial period.
There were zero commits and zero active maintainers in the last three months. Combined with the last push in 2021, this indicates a serious maintenance and abandonment risk.
The artifact declares Apache-2.0 and includes a license file, so licensing is present. However, the detected MIT license conflicts with the declaration, creating a transparency concern.
Only one registry account has publish access. A single maintainer is not inherently unhealthy, but it offers little publishing redundancy when the repository also shows no recent activity.
The artifact is small and contains Composer metadata plus interface and helper source files, but it also includes committed vendor files and IDE metadata. This is untidy packaging rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.