It has a clear license, a matching repository, a small dependency surface, and release notes for this version. The missing tests and security tooling reduce confidence in ongoing maintenance and release safety.
45%
Total Score
0
100
71
75
The package has four releases, all clustered on one day in May 2019, with no releases in the last 12 months and an age of about 7 years 4 months. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long gap since the release history. That leaves little evidence of active maintenance.
Composer is used as a build tool, but no security scanning tooling is present. For a small package this is a meaningful transparency and detection gap, though not severe on its own.
The repository has no security policy. This weakens the project's disclosure and response transparency, particularly alongside the lack of recent maintenance activity.
Version 0.1.2 is not a stable-major release, so the package may have a less mature compatibility promise. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.