The codebase is tiny and the README gives basic integration guidance. Its MIT declaration and direct package-repository match improve transparency, but there is little evidence of ongoing care.
38%
Total Score
50
100
79
83
The repository is owned by an individual account rather than an organization, so there is no organizational backing signal to offset the single-maintainer maintenance risk.
The package has had only two releases, with the latest published in January 2016 and none in the past 12 months. This long release gap is a meaningful abandonment concern.
The repository recorded zero commits and zero active maintainers in the past three months, following a last push in January 2019. This strongly suggests maintenance has stopped.
There have been no new or closed issues or pull requests in the past month, while two pull requests remain open. Combined with the old repository activity, this indicates limited project attention.
The repository has zero stars and two forks, providing little supporting evidence of broad community adoption. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sly/pushover Version * | — | — |
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.