The MIT license, matching repository, and concise README provide basic transparency for consumers. However, this is the only release from about 10 years ago, and the package and repository are both archived, making ongoing fixes and support unlikely.
10%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement supplied. This is a direct warning against adopting the package and outweighs its otherwise valid metadata.
The package has only one release, published about 10 years ago, with no releases in the last 12 months. This strongly indicates abandonment for a dependency intended to track an external API.
The source repository is archived and was last pushed about 10 years ago, so ongoing maintenance and issue response should not be expected.
The repository is owned by an organization, but the separate archival and release evidence shows no active project backing for this package. The organization ownership does not compensate for abandonment.
The repository has no security policy. This is a transparency gap, though it is secondary to the package being deprecated and archived.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.