The package is clearly identified, licensed, documented, and includes release notes for this version. Its single-person ownership and absent security policy provide little resilience if maintenance is needed.
40%
Total Score
25
70
75
Only two releases were published, with the latest about 6 years ago and none in the last 12 months. That long release gap is a strong abandonment concern for a package still labeled beta.
The repository recorded no commits or active maintainers in the measured 3-month period, consistent with the long period since its last release and indicating no recent maintenance.
One registry maintainer is consistent with the repository being owned by an individual, but it provides a thin maintenance base and little redundancy if that person stops supporting the package.
The repository has no security policy. This is a transparency and response-process gap, though it is less significant than the package's long-term inactivity.
The assessed release is still a prerelease, and all recent releases are prereleases. Combined with the absence of later releases, this leaves the package without a demonstrated stable maintenance path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeception/codeception Version ^3.1||^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.