The MIT license and absence of install-time scripts make the package straightforward to inspect and integrate. Its repository has no security policy, while the package-to-repository relationship is unclear, reducing confidence in long-term support.
38%
Total Score
50
78
75
The package has only two releases, both from October 2021, with no releases in nearly five years. This is strong evidence of abandonment for a dependency that may need fixes or compatibility updates.
The repository recorded no commits and no active maintainers in the last three months, consistent with the nearly five-year maintenance gap.
The repository name does not match the package name and its README does not mention the package. This makes the source relationship unclear and raises transparency concerns.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide no evidence of a broad support community.
Composer is used as the build tool, which fits the package, but no security scanning tools are configured. That weakens maintenance hygiene without independently making the release unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.