The project has had no commits or releases for nearly 10 years, with no active contributors and no security policy. It is small but coherent, licensed, documented, tested, and not deprecated or archived.
42%
Total Score
25
50
72
50
The package has had no releases in the last 12 months, and its latest release was published nearly 10 years ago. This is strong evidence of abandonment for a dependency that may need compatibility or bug fixes.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last release. This materially raises abandonment risk.
The package has five runtime dependencies, including three project-specific libraries, which creates some compatibility and transitive-maintenance exposure for an old package.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to compensate for the single-maintainer project profile.
The repository has no stars or forks and only one watcher. Popularity is not required for health, but these counters provide no supporting evidence of a broader maintenance or review community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alc/csv Version ^1.0 | — | — |
symfony/console Version ^3.1 | — | — |
alc/sitemap-crawler Version ^1.0 | — | — |
alc/dom-parser-helper Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.