The package has a clear MIT declaration, a usable README, and no install-time scripts. Its small, inactive project footprint leaves compatibility and maintenance risks unresolved for a modern dependency.
42%
Total Score
0
100
67
75
Only one release exists, published about six years ago, with no releases in the last 12 months. This is strong evidence of an unmaintained dependency.
There were no commits and no active maintainers in the last three months. Combined with the single old release, this indicates a severe abandonment risk.
The repository name does not match the package name and its README does not mention the package. That raises concern that the linked source may be a fork or loosely related repository rather than a clearly maintained home.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no independent sign of an active user or contributor base.
Composer is used for the build, which is appropriate for a Packagist package. No security scanning tools are present, leaving a minor transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.