Its MIT license, matching repository, and zero runtime dependencies reduce adoption friction. The small project has no security policy, so future fixes and oversight are limited.
40%
Total Score
33
100
75
83
The latest release was in September 2015, about 11 years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite five historical releases.
There were zero commits and zero active maintainers in the last three months, consistent with an effectively dormant project and a high risk of unfixed problems.
The repository is owned by an individual account rather than an organization, so there is no provided evidence of broader project backing to compensate for the inactive maintainer base.
There has been no new or closed issue activity in the last month and one issue remains open, providing little evidence of current project support.
Composer is used for the build, but no security scanning tools are present. This is a modest transparency and oversight gap for a package with no recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.