The package is very small and clearly licensed, with an organization-owned repository and no install-time scripts. Its lack of tests and consumer documentation reduces transparency, while the project has seen no release or repository push since July 2021.
43%
Total Score
75
100
57
83
There has been only one release, published about 5 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency, although the package may be intentionally minimal.
The artifact and repository have no tests, changelog, or README. Missing tests and changelog are acceptable for a tiny compiled-style package, but the absent README weakens consumer documentation for a Composer plugin.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a dormant project, though a tiny package may simply receive little feedback.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide no evidence of a broader maintenance community.
Composer is used as the build tool, but no security scanning tooling is reported. The missing scanning is a modest transparency gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.