Its MIT license, README, tests, release notes, and matching source repository make the project easy to inspect. The small dependency set and lack of install scripts reduce routine integration risk, but there is no recent maintenance activity.
42%
Total Score
25
100
72
88
The package has had no releases in the last 12 months, and its latest release was in April 2024 despite being over two years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months. That confirms the release gap reflects inactive development rather than registry-only inactivity.
The registry namespace and repository owner are the same individual account, indicating direct ownership rather than an organization-backed project. This is consistent with the thin maintenance capacity shown elsewhere.
The repository has 4 stars, 0 forks, and 1 watcher. Low adoption is only supporting evidence, but it provides little indication of a broad community that could compensate for a single inactive maintainer.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools are present. The missing scanning is a hygiene concern rather than evidence of unfitness by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
belicfr/mvclite-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.