Usable with caveats: the package is clearly identified, licensed, tested, and documented, but its last release and repository activity date to 2018. Depend on it only if its older PHP and node-jslint integration remains suitable for your project.
58%
Total Score
50
100
78
88
The package has 11 releases since 2013, but none in the last 12 months and the latest release was in April 2018, roughly 8 years ago. This is a meaningful maintenance and compatibility concern despite the established release history.
There are no open issues or pull requests, and no recent issue or pull-request activity. This indicates no visible unresolved queue, but it also offers no evidence of current project engagement.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these very low figures provide little external evidence of ongoing community use.
Composer is used as a build tool, which fits the PHP package, but no security scanning tools are configured. The missing scanner is a transparency gap, though it is not by itself evidence that the package is unsafe.
The linked repository is not archived, but its last push was in April 2018. The lack of archival is positive, while the old last-pushed date still reinforces the maintenance concern from the release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.