The Composer package is small, has no install-time scripts, and is backed by an organization. However, its source has been inactive for nearly four years and the package has no license, making long-term adoption risky.
38%
Total Score
50
50
100
Only four releases were published, with the latest in October 2019 and none in nearly seven years. This strongly indicates abandonment for a package developers may still need to maintain.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and indicating little current maintenance capacity.
No license declaration or license file was detected in the package or repository. That creates a concrete adoption and redistribution concern.
The artifact has no README, tests, or changelog, which limits consumer guidance and transparency. The absence of tests and changelog is normal for published artifacts, but the missing README remains a minor usability gap for this extension package.
The repository name does not match the package name, and no README mention was available. Although a name mismatch can be normal for a sub-package, the lack of a confirming mention leaves some uncertainty about repository alignment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.