Risky to adopt despite strong project backing. The package has had no registry release for over two years and is flagged as borrowing the identity of composer/pcre, while repository tests, release notes, and organization ownership provide meaningful counterevidence.
42%
Total Score
75
100
81
100
The package is reported to borrow the identity of composer/pcre, a much more downloaded package owned by someone else, with no self-described fork or integration evidence. This creates a serious risk that consumers could select the wrong dependency.
The project has 45 releases since 2012, but its latest registry release was June 24, 2024 and it had no releases in the following 12 months. That is a substantial freshness concern for a package supporting many frameworks.
The repository recorded zero commits and zero active maintainers in the most recent three months, indicating little recent development activity. The recent repository push and existing release history provide some context, but not enough to remove the maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.