The package includes tests, a readable README, release notes, and a small runtime dependency surface. Its maintenance has stopped, the registry marks the package abandoned, and the license declaration conflicts with the license detected in the artifact.
18%
Total Score
33
100
61
83
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk even though the assessed release is not individually withdrawn.
The latest release was published in November 2017, and there have been no releases in the last 12 months. The long period without releases strongly indicates abandonment for a dependency last updated years ago.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the old release history and showing no current maintenance capacity.
The artifact contains a license file and the repository also has one, but the manifest declares MIT while the detected license is BSD-3-Clause. That mismatch creates licensing uncertainty for adopters.
The repository is owned by an individual account rather than an organization, so the single registry maintainer does not benefit from visible organizational backing. This modestly increases continuity risk alongside the inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atoum/atoum Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.