The release is stable and clearly licensed, with a small but coherent artifact and an active-looking source repository. However, the package is deprecated and has no releases in the last 12 months or commits in the last 3 months, so pinning it carries substantial adoption risk.
20%
Total Score
50
79
100
Packagist marks the entire package as abandoned and names `sounds` as a replacement. Package-level deprecation is a severe dependency risk even though the repository remains available.
The package has five releases over about three years, but none in the last 12 months and a median release interval of about 210 days. This indicates a very slow release cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months. That weakens evidence of ongoing maintenance, despite a recorded recent push outside this measurement window.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pocketmine/pocketmine-mp Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.