MIT licensing and a small, internally consistent artifact keep adoption straightforward. The linked organization and matching README improve provenance, while the stable version avoids prerelease uncertainty.
38%
Total Score
0
86
50
The last registry release was about four years ago, with no releases in the past year. That strongly indicates abandonment risk despite a long publication history and 22 total releases.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the extended release gap and leaving little evidence of ongoing maintenance.
The package uses post-install and post-update Composer scripts, so installation executes package-provided code. These hooks are central to its stated autoloader-generation behavior but still increase operational and review risk.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a hygiene gap, though it does not outweigh the clearer maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.