The small codebase has a README, tests, and no runtime dependencies, which limits adoption friction. Its clear license and straightforward packaging help, but the project provides little evidence of current maintenance.
38%
Total Score
50
100
50
50
The latest release was in June 2014, with no releases in the last 12 months and only two releases overall. This is strong evidence of abandonment risk for a dependency.
The repository is not archived, but its last push was in June 2014, matching the stale release history and leaving current maintenance uncertain.
The repository is owned by an individual account rather than an organization, so there is no observed organizational backing to compensate for the single-publisher and inactive-project signals.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no additional community signal to offset the long inactivity.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is present. This is a modest transparency and maintenance gap rather than a standalone blocker.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.