The README, tests, matching repository, and MIT license provide useful transparency for this small library. Its lone maintainer and minimal adoption offer little evidence of ongoing support, so pinning this old release carries maintenance risk.
42%
Total Score
25
100
71
100
The package has only one release, published nearly 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package remaining non-deprecated.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no update since 2016. There is no observed recent maintenance capacity.
One registry publishing maintainer is listed, providing a thin support base. The linked repository is user-owned rather than organization-backed, so no broader backing is shown to compensate.
The repository has only 2 stars, 3 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little community support to offset the lack of activity.
Composer is used as the build tool, which fits the ecosystem and supports reproducible project setup. No security scanning tool is present, but this is a secondary hygiene gap for this small, inactive package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.