The codebase is small and straightforward to inspect, with MIT licensing and no install-time scripts. Maintenance capacity and security coverage are limited, so long-term fixes and support are uncertain.
38%
Total Score
25
100
69
75
The latest release was in November 2017, with no releases in the last 12 months despite the package being nearly 9 years old. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months. Combined with the old last release, this indicates the project is not being maintained.
A README is present and the repository uses GitHub releases, but the package and repository contain no tests or changelog. The missing tests are a modest maturity gap for a utility library.
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational maintenance backing. This matters more given the lack of recent activity.
Composer build tooling is present, but no security-scanning tool was detected. The lack of scanning is a hygiene gap, especially for a dependency that has seen no recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.