The package has a usable README, a matching source repository, and an MIT license. Its single-maintainer project has no security policy or scanning, leaving limited maintenance and security transparency.
42%
Total Score
33
100
71
83
Only two releases exist, and the latest was published about seven years ago with none in the last 12 months. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having stopped receiving updates years ago.
Registry publishing access is held by one maintainer. Because the repository is user-owned rather than organization-backed, this indicates a thin publishing and continuity base.
The repository is owned by an individual user, not an organization. That is not inherently unhealthy, but it offers less visible continuity backing for an already inactive package.
Composer is used for the build, but no security scanning tools are configured. That weakens ongoing security hygiene, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hanson/foundation-sdk Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.