A single maintainer, no security policy, and no security scanning reduce confidence in long-term support. The repository is not archived and the package declares MIT licensing, but the package-to-repository naming mismatch needs verification.
38%
Total Score
25
69
50
The latest release was about four years ago, with no releases in the last 12 months. Despite 106 historical releases, this strongly indicates the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Only one registry account has publish access. That is a thin publishing base for a broad framework-like package and increases continuity risk alongside the lack of recent activity.
The package contains no readme, tests, or changelog, reducing transparency for a library consumers must integrate. The absence of tests and changelog in the published artifact is otherwise normal packaging practice.
The repository name does not match andesite/core, and the package name was not found in the repository README. That raises uncertainty about whether the linked source is the intended project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rah/danpu Version ^2.7 | — | — |
twig/twig Version ^2.0 | — | — |
symfony/yaml Version ^4.2 | — | — |
redant/console Version ^1.0 | — | — |
clue/socket-raw Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.