Clear documentation, tests, and a matching MIT license make the code easier to evaluate. Its maintenance and package-identity concerns still make adopting this old release a liability.
38%
Total Score
50
100
50
50
The package has had no release in about 10 years and none in the last 12 months, with only three releases overall. This is strong evidence of abandonment, despite the package not being registry-deprecated.
The repository name does not match the package name, and its README does not mention this package. The README instead documents a differently named Composer package, creating a material package-identity and publishing-transparency concern.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with the long maintenance gap, though a small stable project may naturally receive little issue traffic.
The repository is not archived, but it was last pushed about 10 years ago. That leaves the project formally available while providing little evidence of current maintenance.
The repository has no security policy or security-scanning tools. That is a transparency and maintenance gap, although the small project and otherwise inspectable source provide limited compensation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.