The package has an MIT declaration, a matching source repository, and a release note, but its maintenance record is effectively dormant. No commits or releases have appeared for over 11 years, leaving compatibility and abandonment risk high.
30%
Total Score
50
64
75
This package has only one release, published over 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and lack of ongoing maintenance.
Composer is used as a build tool, but no security scanning tooling is present. This is a hygiene gap, though it is secondary to the package's prolonged inactivity.
The linked repository is not archived, which is a modest compensating signal, but its last push was over 11 years ago and does not offset the dormant activity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This matters more because the project shows no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atuin/apps Version * | — | — |
atuin/menus Version * | — | — |
atuin/config Version * | — | — |
yiisoft/yii2 Version >=2.0.4 | — | — |
atuin/skeleton Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.