It includes a substantial test suite, a clear README, and a repository that matches the package. The declared BSD-3-Clause license conflicts with the detected Apache-2.0 file, and the repository has no security policy.
12%
Total Score
50
42
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption and maintenance warning for a dependency.
The package has had no releases in over seven years despite being published since 2016. This strongly indicates that the release line is no longer maintained.
The repository had zero commits and zero active maintainers in the last three months. Combined with the archived status, this provides no evidence of ongoing maintenance.
The linked repository is archived, and its last push was in January 2021. Archived source is a severe abandonment risk even when the code remains available.
A BSD-3-Clause license is declared, but the artifact license file is detected as Apache-2.0. The mismatch creates legal ambiguity for consumers despite both the artifact and repository containing license files.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pear/console_commandline Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.