It is MIT-licensed, has a README, a small dependency surface, and no install scripts. The source appears tied to the package, but its thin project footprint limits confidence in ongoing compatibility.
42%
Total Score
50
75
83
This is the only release, published over 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its last push being over 10 years ago. This materially increases abandonment and compatibility risk.
The linked repository name does not match the package name and its README does not mention the package, so the repository relationship is not fully transparent. The repository URL itself is package-specific, which partly offsets the concern.
The repository uses Composer build tooling, but no security scanning tools are reported. Composer support is appropriate; the missing scanning is a minor hygiene gap.
The repository has no security policy. This is a transparency and response-process gap, though it is less significant than the long period without maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
propel/propel Version ~2.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.