Risky to adopt: the latest release was over eight years ago and the repository has had no commits or active maintainers in the last three months. It has a README, matching source repository, and no install scripts, but the release has no license and shows little evidence of ongoing support.
32%
Total Score
50
100
64
88
The package has made three releases since 2015, with no release in more than eight years and none in the last 12 months. This is strong evidence of abandonment for a tool that may need compatibility updates.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this indicates no current maintenance capacity.
Neither a license declaration nor a license file was found, leaving the legal terms for using and redistributing this package unclear.
Composer is used as a build tool, but no security scanning tooling is present. For this small CLI project that is a modest transparency gap rather than a standalone severe risk.
The repository is not marked archived, which avoids the strongest abandonment signal, but its last push was over eight years ago and does not compensate for the stale release history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
memio/memio Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.