The package is small, clearly identified, licensed under MIT, and includes tests, a README, and release notes. Its minimal dependency set and lack of install scripts reduce integration risk, but the project shows little evidence of ongoing care.
40%
Total Score
50
100
72
75
The latest release was published nearly 13 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk despite the package having reached a stable version.
The repository is owned by an individual rather than an organization, so the single registry maintainer is consistent with the available project backing but offers limited continuity.
There are no open issues or pull requests and no recent activity. While that may reflect a small stable project, it provides no evidence of active maintenance.
The repository has 4 stars and 1 fork, providing little evidence of broad community adoption; popularity is supporting evidence rather than a verdict.
Composer is used for the build, but no security scanning tools are reported. This is a modest transparency gap, secondary to the much older maintenance history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.