It is MIT-licensed, not deprecated, and the repository matches the package. The long-running lack of maintenance makes this a legacy dependency with substantial abandonment risk.
38%
Total Score
75
88
75
The latest release was over eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the stable 1.1 version.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's prolonged release inactivity.
The repository has only 2 stars and no forks, providing little community evidence to offset the lack of recent maintenance.
The linked repository has no security policy or security scanning tooling. This adds a transparency and maintenance concern, though it is secondary to the inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
avored/ecommerce Version 1.* | — | — |
avored/module-installer Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.