The MIT declaration is clear, and the repository remains available. Its small scaffold and five runtime dependencies provide limited evidence about long-term support.
38%
Total Score
25
75
50
The package has had only two releases, both in June 2015, with no release in about 11 years. That is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the very old release history and indicating no current maintenance.
Only one registry account has publish access. With no recent release or commit activity, this leaves little visible maintenance capacity or continuity.
Composer build tooling is present, but no security-scanning tooling was detected. The build setup is a modest positive, while the missing scanning reduces project hygiene evidence.
The repository has no security policy. This is a transparency and response-process gap, though it is less significant than the prolonged lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bc/cmf Version >=0.1.6 | — | — |
bc/pdo Version 0.1.* | — | — |
bc/model Version >=0.1 | — | — |
bc/memcacher Version >=0.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.