Tests and release notes improve transparency, while the artifact has no license declaration or file. Its small dependency set and organization-backed repository offer little compensation for the package's long-term inactivity.
12%
Total Score
50
36
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct adoption warning and outweighs otherwise modestly positive metadata.
The package has had no releases in more than nine years: its latest release was July 23, 2017, and it has no releases in the last 12 months. This indicates sustained abandonment.
There were zero commits and zero active maintainers in the last three months, consistent with the repository being abandoned. No current development activity compensates for this gap.
The linked repository is archived and was last pushed on July 23, 2017. Archived source is a severe abandonment risk for a dependency.
No declared license, recognized license text, or license file was found in the package or repository. This creates a material legal and transparency gap for adopters.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
consigliere/siegnor Version 0.3.* | — | — |
consigliere/signature Version 0.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.