The release contains tests, a README, and release notes, with a matching organization-backed repository. The repository has no recent commits or security scanning, limiting confidence in future fixes.
15%
Total Score
75
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk even though the specific release is not separately withdrawn.
The linked source repository is archived, so it is unlikely to receive maintenance or fixes. Its last push was in July 2023, reinforcing the abandonment concern.
Only three releases exist, and there have been no releases in the last 12 months; the latest release was in June 2023. This indicates an inactive release cadence alongside the abandonment signals.
There were zero commits and zero active maintainers in the last three months. The archived state explains this, but it still leaves defects and dependency compatibility issues without an active fix path.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a secondary concern because the package is already marked abandoned and archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
packaged/ui Version ^1.7 | — | — |
packaged/context Version ^1.0 | — | — |
packaged/helpers Version ^1.0|^2.0 | — | — |
packaged/safehtml Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.