The small codebase is clearly packaged, licensed, documented, and tied to its repository. Install-time scripts, no security policy, and limited project reach add meaningful maintenance and hygiene concerns.
48%
Total Score
50
100
75
67
The latest release was in May 2018, more than eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, although the package is small and stable.
post-install-cmd and post-update-cmd scripts run during dependency operations. This adds install-time behavior that should be understood before adoption, even though no maliciousness conclusion follows from it.
Only one registry maintainer is listed. That is workable for a small user-owned package, but it leaves limited visible publishing resilience if the maintainer stops responding.
The repository is owned by an individual rather than an organization. That is consistent with a small package, but it offers less visible institutional backing for long-term maintenance.
There is one open issue and no issue or pull-request activity in the last month. Combined with the old last push, this supports a conclusion of inactive maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.