Risky to depend on: this is a minimal package with no license and no activity since March 2021. It is not deprecated or archived, but its tiny repository and long-term inactivity make maintenance and reuse a liability.
28%
Total Score
50
75
83
The package is over five years old, has only 3 releases, and has had no release in the last 12 months. This is strong evidence of abandonment rather than an actively maintained dependency.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the last push occurring in March 2021. The prolonged lack of development materially increases maintenance risk.
No declared license or license file was found in the package or repository. That leaves developers without clear permission to use, modify, or redistribute the dependency.
The registry lists one publishing maintainer. The organization-owned repository provides some backing context, so the short registry list is not itself a severe concern, but it offers little evidence of an active maintainer base.
The package and repository each contain only composer.json, showing an unusually minimal project with little visible implementation or supporting material. This may be intentional for a test package, but it provides very limited transparency for a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.