Risky to adopt for a new project: it has had only one release, with no registry releases for over 10 years and no repository commits for over 8 years. The package is small but understandable, with tests, a README, and no deprecation or install-time scripts.
45%
Total Score
25
100
69
83
This package has only one release, published over 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the repository remaining available.
The repository has recorded no commits and no active maintainers in the last 3 months, consistent with the last push being over 8 years ago. The lack of recent maintenance is a significant concern for a dependency.
The registry namespace and repository owner match, providing consistent ownership evidence. The owner is an individual account, so there is no organization-backed maintainer capacity to offset the long inactivity.
Composer is used as a build tool, but no security scanning tooling is present. The missing scanning is a transparency gap, though the repository's small and inspectable file tree limits its weight.
The linked repository is not archived, although its last push was over 8 years ago. The active archive status is a positive signal but does not compensate for the observed inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.