Its small source tree, MIT license, and lack of install-time scripts keep the package straightforward to inspect. The project has seen no new release or repository push for over six years, leaving maintenance and compatibility uncertain.
42%
Total Score
50
67
67
This is the only release, published over six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the package may be intentionally minimal.
The package contains only seven files, including a README, manifest, and one source file. This is consistent with a tiny package but provides little evidence of maturity or maintenance depth.
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not have broader organizational backing to compensate for the limited maintenance evidence.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external indication of active use or community support.
Composer is used for the build, but no security scanning tool is configured. For a very small package this is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.