The package has a useful README, repository tests, stable versioning, and no install-time scripts. Its single maintainer and absent security scanning add smaller concerns, while the package should be replaced because it is deprecated and has had no commits or releases for about three years.
15%
Total Score
50
57
75
Packagist marks the entire package as abandoned, with no distinct replacement identified. Package-wide deprecation is a severe dependency risk even though the assessed version is stable.
The package has only four releases and none in the last 12 months; its latest release was about three years ago. This indicates a prolonged lack of maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The linked repository is not archived, which provides only limited compensation.
A license file is present and the repository also contains one, so licensing is not absent. However, the manifest declares MIT while the artifact license is detected as MIT-0, creating a license mismatch that should be clarified.
The repository uses Composer build tooling, but no security scanning tools were detected. That weakens ongoing dependency and code hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.