The package has a declared license, a README, and only one runtime dependency. Its source repository matches the package and is not archived, but the project shows no recent maintenance or security tooling.
38%
Total Score
50
100
81
50
This is the package’s only release, published in 2018, with no releases in the last 12 months. That long-standing lack of release activity raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, providing no evidence of ongoing maintenance to offset the old release history.
There were no new or closed issues or pull requests in the last month. This supports the picture of a dormant project, although it does not by itself prove the code is unusable.
The repository has zero stars, forks, and watchers, so there is little visible community adoption or external support to compensate for its inactivity.
Composer build tooling is present, but no security scanning tools were detected. That is a maintenance and transparency gap for a package that has otherwise seen no recent activity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.