Usable with caveats: this is a small, clearly licensed package with a real source repository and no deprecation or install-time scripts. Adoption carries maintenance risk because it has only one release, no commits in about 7 months, and limited project hygiene for a work-in-progress implementation.
50%
Total Score
50
83
50
The package is about 7 months old but has only one release, so there is little evidence of an established release process or ongoing delivery.
The repository recorded no commits and no active maintainers during the last 3 months, leaving current maintenance capacity un demonstrated and increasing abandonment risk.
The repository has only 1 star and 1 fork, indicating a very small user and contributor footprint. Low popularity is supporting evidence rather than a defect, but it offers little external resilience.
Composer and Make tooling are present, showing some project structure, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package intended for plugin developers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pocketmine/pocketmine-mp Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.