The package is very small and easy to inspect, with one runtime dependency, a matching MIT license, and clear usage documentation. Its source has seen no release or push activity for about 10 years, with no tests or security policy, so maintenance support is effectively absent.
38%
Total Score
75
100
67
83
The package has only 3 releases, all concentrated in July 2016, and none in the last 12 months; the latest release is about 10 years old. This is strong evidence of abandonment for a dependency that may need compatibility fixes.
There are no open issues or pull requests and no recent activity. For this tiny package that is not inherently bad, but together with the old release date it provides no evidence of ongoing maintenance.
The repository uses Composer for builds, but has no security-scanning tools. The straightforward project structure makes this a modest hygiene gap rather than a severe risk.
The repository is not archived, which avoids an explicit abandonment marker, but its last push was about 10 years ago and does not offset the stale release history.
The repository has no security policy. This is a transparency gap, especially for a package that edits environment files, although the small codebase limits the impact compared with a larger dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.