The package includes a matching source repository and a clear usage README. Its very small codebase lacks tests and security scanning, leaving little evidence of ongoing care. The stable version and lack of install scripts reduce immediate adoption risk, but not abandonment risk.
38%
Total Score
0
64
75
The latest release was published in October 2017, with no releases in the last 12 months. Nearly nine years without a release is strong evidence of abandonment risk, despite the nine historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing that development stopped years ago.
The artifact includes a README, which supports basic consumer understanding. Missing tests and a changelog are normal for published artifacts under these rules, while the absence of repository tests provides no compensating maintenance evidence.
The linked repository has one star, zero forks, and one watcher, offering little supporting evidence of community review or adoption. Low popularity alone is not decisive for a small package, but it provides no counterweight to the stale maintenance signals.
Composer is used as a build tool, but the repository has no security scanning tools. This is a hygiene gap that adds modest transparency and maintenance concern rather than an immediate dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.