Risky to adopt: the package has had no release or repository activity for more than 10 years. It is small, licensed, documented, tested, and free of install scripts, but its maintenance appears effectively abandoned.
38%
Total Score
50
100
72
83
The latest release was published in June 2015, with no releases in the last 12 months despite the package being over 11 years old. This is strong evidence that the dependency is no longer maintained.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, and its last push was in October 2015. The long absence of development materially increases abandonment risk.
The repository has 0 stars and 0 forks, with 14 watchers. Low popularity is supporting evidence rather than a verdict, but it provides little external evidence of ongoing adoption or review.
Composer is used as a build tool, but no security scanning tools are present. For this small, inactive repository the missing scanning is a transparency gap, though it is less significant than the maintenance risk.
The repository is not formally archived, which avoids a definitive abandonment marker, but its last push was in 2015 and this does not compensate for the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.