Its only two releases arrived 19 days apart in 2013, with no release in nearly 13 years. One maintainer and a repository that could not be found leave maintenance and provenance unverified.
8%
Total Score
50
100
17
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe warning against taking a new dependency on it.
The package has only two releases, both from 2013, and no release in nearly 13 years. This strongly indicates abandonment risk.
Only one account has publish access, leaving little visible maintenance capacity when combined with the package's lack of recent releases.
The latest version is v0.1.1 rather than a stable major release, adding maturity concerns on top of the long period without updates.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.