Tests, a substantial README, and matching MIT licensing improve transparency. The project has no security scanning and its small codebase has seen no maintenance for over 12 years, so this old prerelease carries substantial abandonment risk.
32%
Total Score
25
58
50
The package has had no release in over 12 years, with all four releases clustered on one day in March 2014. That is strong evidence of abandonment for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in March 2014. This confirms the long release gap is not just a registry artifact.
There has been no issue or pull-request activity in the last month and no open work. Although a quiet issue tracker can be benign, here it reinforces the absence of ongoing maintenance.
The repository name matches the package, reducing the risk of an unrelated source repository, but the README does not mention the package name. This mismatch creates a minor provenance concern.
Composer is used for the build, which is appropriate for this Packagist package, but no security scanning tool is present. That is a modest supply-chain hygiene gap rather than evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-cli/php-cli-tools Version v0.9.4 | — | — |
zendframework/zend-session Version 2.* | — | — |
jeremykendall/password-validator Version dev-develop | — | — |
zendframework/zend-authentication Version 2.* | — | — |
zendframework/zend-permissions-acl Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.