The source repository is identifiable and includes tests, a changelog, documentation, and a matching MIT license. Its single-person ownership and lack of security scanning add maintenance uncertainty for an abandoned release line.
32%
Total Score
50
67
88
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on this release line.
The package has only one release, published over 11 years ago, and none in the last 12 months. That indicates a long-abandoned release line rather than an actively maintained dependency.
Only one registry maintainer is listed, and the project is backed by an individual repository owner rather than an organization. Combined with the lack of recent activity, this leaves a thin maintenance base.
The repository recorded no commits or active maintainers in the last 3 months, and its last push was in 2018. This confirms that current maintenance is unlikely.
There were no new or closed issues or pull requests in the last month, while 10 issues remain open. This provides no evidence of active issue maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
components/jquery Version >1.5.2 | — | — |
components/modernizr Version dev-master | — | — |
robloach/component-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.