The source is small and tested, with no install-time scripts; its lone maintainer and missing security policy leave little evidence of resilience. The package is transparent enough to inspect, but maintenance capacity looks weak.
38%
Total Score
25
63
75
This is the package's only release, published about 13 years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite the stable 1.0.0 version.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and providing no evidence of ongoing maintenance.
Only one registry account has publish access. That is a thin publishing base for an old package and increases continuity risk, with no organizational backing shown to compensate.
The repository name does not match the package name and its README does not mention the package. This weakens confidence that the linked source clearly documents the published dependency.
The linked repository has no security policy. For a package this old, the absence of documented reporting and response procedures is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
barberry/interfaces Version 1.1.* | — | — |
barberry/plugin-installer Version 1.0.* | — | — |
barberry/plugin-imagemagick Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.