The package has a clear MIT license, readable setup instructions, tests, and a matching source repository. It lacks a security policy and repository security scanning, leaving limited evidence of ongoing project care.
38%
Total Score
50
100
72
88
This is a 9-year-old package with only one release, published in April 2017, and no releases in the last 12 months. That strongly increases abandonment risk.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This offers limited backing evidence and does not offset the stale activity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to compensate for the stale release history.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces supply-chain maintenance evidence without making the release unsafe by itself.
The repository is not archived, which is a compensating signal, but it was last pushed in April 2017 and does not offset the long period without visible maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.