Risky to adopt: this package has had only one release, with no repository activity for over six years. It is small and transparent with an MIT license and a matching source repository, but the lack of maintenance makes abandonment a significant concern.
40%
Total Score
50
100
64
75
There has been only one release, published over six years ago, with no releases in the last 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long-term maintenance concern.
There are no open issues or pull requests and no recent issue or pull request activity. This is consistent with an inactive project, although it does not by itself show unresolved maintenance problems.
The repository has zero stars and forks and only one watcher. Low popularity is not decisive for a small package, but it provides little supporting evidence of active community use.
Composer is used as a build tool, but no security-scanning tooling is present. The missing scanning is a hygiene gap, while the stronger concern remains the project's prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.