Very simple asset manager
38%
Total Score
unhealthy
Risky: the only release is over 12 years old and the project has no recent commits.
There has been only one release, published over 12 years ago, with no releases in the past 12 months. This is strong evidence of abandonment for a library dependency.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the long period since the last release, this indicates likely abandonment.
Five runtime dependencies create a meaningful maintenance surface for a small, old package, especially because dependency compatibility cannot be inferred from recent project activity.
A license file is present, but the manifest declares BSD-4-Clause while the artifact and repository license are detected as BSD-3-Clause. The mismatch reduces transparency even though the release is licensed.
The repository has only 3 stars and no forks, providing little evidence of broad community validation. Popularity is supporting evidence rather than a verdict on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafo/lessphp Version * | — | — |
leafo/scssphp Version * | — | — |
crodas/file-util Version >=0.1.7 | — | — |
patchwork/jsqueeze Version * | — | — |
crodas/service-provider Version >=0.1.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.