The artifact is simple and clearly documented, with an MIT declaration and a README. Its six-release history and single-person ownership offer little maintenance capacity, while activity has been absent since 2019. Adopt only if its limited scope and unchanged code fit your needs.
42%
Total Score
25
81
83
The latest release was in January 2019, about 7 years ago, and there were no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency that may need fixes.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. No provided maintenance signal compensates for this inactivity.
Only one registry maintainer is listed, which limits publishing continuity. The repository is user-owned rather than organization-backed, and recent activity does not show an active maintainer base.
Composer is used as the build and dependency tool, but no security scanning tooling is present. This is a modest transparency and maintenance gap for a package with otherwise very limited project activity.
The repository has no security policy. For a small, inactive package this makes vulnerability reporting less transparent, although it is secondary to the prolonged maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.