Risky to adopt: the package has had no release or commit activity for nearly six years and provides no README or tests. Its MIT license, tiny dependency surface, and organization-backed repository reduce transparency and maintenance concerns but do not offset the abandonment risk.
42%
Total Score
50
100
64
83
Only two releases were published, with the latest nearly six years ago and none in the last 12 months. This is strong evidence of an inactive project, although the package may be intentionally stable.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the last release. No provided signal shows ongoing maintenance.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The very small five-file utility may not need extensive scaffolding, but the missing README makes adoption and maintenance harder to assess.
The repository has zero stars and forks and only one watcher, providing little evidence of external use or community visibility. Popularity is supporting evidence rather than a verdict, so this is a secondary concern.
Composer is used for builds, but no security-scanning tooling is configured. With no workflows or recent activity, this leaves limited evidence of continuing project hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.