The package is well documented, tested, licensed, and backed by an organization, which reduces transparency and ownership concerns. Low adoption, no recent issue activity, and missing security tooling provide little evidence of ongoing care.
42%
Total Score
50
63
50
The latest release was about seven years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk even though the package has nine releases overall.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this materially raises abandonment risk.
Six issues remain open, with no new or closed issues and no pull-request activity in the last month. This is consistent with limited ongoing project attention.
The repository has six stars and no forks, indicating a very small user and contributor community. Small size is not disqualifying, but it provides little external maintenance support.
The repository uses Composer, but no security-scanning tools were detected. That is a maintenance and transparency gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xrstf/composer-php52 Version ^1 | — | — |
brightnucleus/config-52 Version ^0.1 | — | — |
brightnucleus/php-releases Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.