It includes a README, release notes for 1.1, and no install-time scripts, which help transparency. One registry maintainer, no security policy, and no security scanning leave limited ongoing oversight.
38%
Total Score
25
71
75
The package has had only two releases, both in 2018, with no release in nearly eight years. This is strong evidence of abandonment risk despite the short initial six-day release interval.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
A GPL-3.0 manifest declaration and license file are present, but the artifact license file is detected as LGPL-3.0. The conflicting license signals create a meaningful adoption and compliance concern.
Only one account has registry publishing access. That is a thin maintainer base for continuity, although the linked repository is owned by the same individual.
Composer is used as the build tool, which supports reproducible package structure, but no security scanning tool is configured. The missing scanning is a minor hygiene gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.