The release is a prerelease from about seven years ago, and all recent repository commits come from one contributor. The MIT license, active organization-owned repository, and lack of install scripts are positive, but the package is intended only as backend assets.
20%
Total Score
83
100
56
75
Packagist marks the entire package as abandoned and identifies bolt/assets as the replacement. This is a direct reason not to start depending on this package.
The package has had no release in about seven years, despite six releases concentrated in its first month. That makes this specific release stale and raises abandonment risk.
One contributor made all five commits in the last three months. Organization ownership provides some handoff capacity, but the observed activity remains concentrated.
The repository name does not match the package name and its README does not mention bolt/bolt-assets. Although name differences are normal for subpackages, the combination leaves package ownership less transparent.
The repository uses Composer for builds but reports no security-scanning tools. That leaves security hygiene less visible, while the small asset-focused scope limits the impact.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.