The package is licensed, documented, tested, and has no install-time scripts. Its source repository has had no recent work and does not identify this package, leaving maintenance and ownership unclear.
38%
Total Score
0
100
72
83
This is the package's only release, published about 6 years and 11 months ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and limited evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. A name mismatch can be normal for a subpackage, but with no README reference this leaves package ownership unclear.
The linked repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a decisive health measure, but it provides no sign of an active user or contributor community.
The repository uses Composer, but no security scanning tools were detected. The build tooling is a modest positive; the absent scanning is a minor hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.