It includes tests, a clear README, release notes, and an identifiable organization-backed source project. The package’s long inactivity and lookalike identity make adopting this release a liability.
35%
Total Score
50
63
67
The package is identified as borrowing the identity of the much more established codeception/codeception package, with 0 monthly downloads versus about 1.5 million for the lookalike. Although artifact overlap is low, consumers may have intended the lookalike package instead.
The package has had no release in over six years: its latest release was January 2020, despite being more than nine years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest registry release, this materially increases abandonment risk.
There is only one open issue and no issues or pull requests were created or closed in the last month, indicating little current project activity.
The project uses Composer, but no security scanning tooling was detected. For a maintained application project, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.