The repository is a small, matching source tree with one maintainer and no observed community activity. It is not deprecated or archived, and installation has no lifecycle scripts, but long-term support is uncertain.
38%
Total Score
63
75
The latest release was in August 2016, with no releases in the last 12 months and only two releases overall. This long period without a release is strong evidence of abandonment risk.
The package includes a substantive README, but both the artifact and repository report no tests or changelog. Missing tests are a meaningful maturity gap for a filesystem library, even though compiled-artifact packaging can explain their absence from the package.
The repository has zero stars and forks and only one watcher, providing little evidence of external adoption or community support. Popularity is supporting evidence rather than a verdict on its own.
Composer is used for the build, but no security-scanning tooling is reported. This weakens release hygiene, although the small project scope limits the significance of the gap.
The linked repository is not archived, which is a compensating sign, but it was last pushed in September 2016 and therefore does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amekusa/plz Version <1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.