Risky to adopt: the latest release was published nearly nine years ago and the repository has had no commits in the last three months. It is not deprecated or archived and has a clear MIT license, but the very small project footprint and repository/package mismatch make ongoing support uncertain.
42%
Total Score
50
100
56
83
The package has four releases, but none in the last nine years; the latest release was published on March 10, 2017. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the last push in 2020, this materially increases abandonment risk.
The published artifact lacks a README, tests, and changelog, but those omissions are normal for many compiled or minimal packages; the repository file tree does include a README. The absence of repository tests and changelog is a modest transparency concern for a library.
There are no open issues or pull requests and no activity in the last month. A clean issue tracker can be positive, but here it offers no evidence of active maintenance.
The repository name does not match the package name and its README does not mention the package. This raises uncertainty about whether the linked repository is the package's actual source, despite the matching owner namespace.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bricks81/bricks-event Version * | — | — |
zendframework/zend-config Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.