The small codebase is clearly documented, MIT-licensed, and has no install-time scripts or dependency sprawl. However, its maintenance and security coverage are weak, making long-term reliance a liability.
38%
Total Score
0
58
75
Only one release was published, on February 28, 2019, with no releases in the past seven years. That strongly suggests the package is dormant, although the single stable release avoids prerelease uncertainty.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's long period without releases. No provided maintenance signal compensates for this inactivity.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad user or contributor base.
Composer build tooling is present, but no security scanning tools were detected. This is a maintenance and transparency gap for a package with no recent activity.
The linked repository is not archived, which preserves the possibility of future maintenance, but its last push was over seven years ago. The non-archived state does not offset the observed inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.