Its repository has no package-name match or README mention, and it has no security policy. MIT licensing and a small, clear artifact help transparency but do not offset abandonment.
18%
Total Score
0
38
83
Packagist marks the entire package as abandoned, with no replacement identified. This is a direct adoption warning and outweighs the otherwise valid package metadata.
This is the only release, published in July 2019, with no releases in the past 12 months. The resulting multi-year inactivity indicates a strong abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's long release hiatus. There is no provided maintenance evidence to offset this.
The linked repository name does not match the package name and its README does not mention the package. That weakens confidence that the repository clearly documents and supports this package.
The linked repository has no security policy. For a small package this is a transparency gap, though it is less significant than the abandonment indicators.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hprose/hprose Version v2.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.