Tests, a substantial README, GPL-3.0 licensing, and a small dependency set provide useful baseline transparency. However, the package has had no releases since January 2017 and its source repository is archived, so it should not be adopted.
12%
Total Score
50
100
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The latest release was published in January 2017, with zero releases in the last 12 months. This long release gap materially raises abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms there is no current development activity to offset the old release history.
The linked AOEpeople repository is archived, even though it was last pushed in June 2023. Archived source indicates maintenance has ended and future fixes are unlikely.
The repository has no security policy and no security scanning tools were detected. This is a transparency and maintenance gap, although it is secondary to the abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mustangostang/spyc Version 0.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.