Risky to depend on: this package has had only one release, published over seven years ago, and its linked repository stopped receiving updates shortly afterward. The repository also does not identify or document this package, creating uncertainty about whether it is the intended source.
35%
Total Score
57
75
There is only one release, and no release has been published in more than seven years. That strongly suggests abandonment and leaves no demonstrated maintenance cadence.
The repository is not archived, but its last push was more than seven years ago, so the active status does not compensate for the long period without updates.
The repository name does not match the package name and its README does not mention the package. This weakens source transparency and raises uncertainty about whether the repository actually backs this release.
Composer is used for the build, but no security scanning tools are configured. This is a modest transparency gap, secondary to the package's much more significant maintenance concerns.
The repository has no security policy. For a package that can be integrated into applications, this makes vulnerability reporting less clear, although it is less serious than the lack of ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.