The MIT license, matching repository, readable README, and minimal dependency surface make the package transparent and simple to adopt. However, it has had no commits or releases for about six years, with no recent issue activity or security policy, so compatibility and maintenance risk are substantial.
44%
Total Score
25
100
75
75
The package has only two releases, both published about six years ago, and none in the last 12 months. This strongly indicates abandonment or a lack of ongoing compatibility work.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided signal shows current maintenance capacity.
There were no new or merged pull requests and no issue activity in the last month. This supports the maintenance concern, although the open-issue count is unknown.
The repository has zero stars, forks, and watchers, providing no community adoption or review evidence. Popularity is supporting evidence only, so this adds limited caution rather than determining the score.
The repository has no security policy. For a Composer plugin that affects autoloading behavior, this reduces vulnerability-reporting transparency, though it is less serious than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.