Its dependency set is substantial for a small package, and one maintainer carries the publishing role. The stable version and lack of install-time scripts reduce immediate friction, but the project provides little consumer documentation.
38%
Total Score
50
50
58
100
No license is declared, and neither the artifact nor the linked repository contains a recognized license file. This leaves developers without clear permission to use or redistribute the package.
The package has had only two releases, both in June 2016, with no release in roughly 10 years. That strongly indicates abandonment risk despite the short initial release interval.
Six runtime dependencies, including Behat and Drupal extensions, create meaningful transitive maintenance and compatibility exposure for a package that has not released in years.
One individual has registry publishing access. A single maintainer is not inherently unhealthy for a small package, but here it provides little evidence of continuing maintenance capacity alongside the long release gap.
The package has no README, while repository tests and a changelog are also absent. Missing tests and changelog are normal packaging gaps, but the missing consumer documentation is a minor transparency concern for a library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version >v2.4@stable | — | — |
behat/common-formatters Version 1.2.* | — | — |
drupal/drupal-extension Version ~1.0 | — | — |
webignition/json-pretty-print Version @dev | — | — |
hasbridge/json-schema-validator Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.