The package includes a usable README and a clearly owned, compact codebase. Its license records disagree, and the project has no recent maintenance evidence, so pinning this old release carries meaningful abandonment risk.
38%
Total Score
50
50
The latest release was published in November 2019, about 6 years and 10 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package having five total releases.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. The repository is not archived, but there is no observed activity to offset the inactivity.
The manifest declares the package proprietary while the repository license file is identified as BSD-3-Clause. This mismatch creates a material licensing ambiguity for adopters.
The repository name matches the package, which supports the repository link, but the README does not mention the package by name. This leaves a modest concern about package-to-repository transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bseries/base_core Version ^1.5 | — | — |
bseries/base_media Version ^1.5 | — | — |
unionofrad/lithium Version ^1.1 | — | — |
composer/installers Version 1.*@stable | — | — |
bseries/ecommerce_core Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.