Its MIT license, focused dependency set, and release notes help with adoption. The one-person project has no security policy or scanning, reinforcing its legacy status.
43%
Total Score
25
100
71
75
The package has had only two releases, with none in about 9 years; its last release was in July 2017. This is strong evidence of abandonment risk despite the short initial release interval.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was in July 2017. This confirms that the long release gap reflects inactive development.
Only one registry maintainer is listed, leaving little visible publishing redundancy. The repository is also owned by that individual, so this is a modest concern rather than a severe risk on its own.
The repository has zero stars and one fork, providing little evidence of community adoption or external support. Popularity is supporting evidence, so this reinforces but does not establish the maintenance concern.
Composer is used for builds, but no security-scanning tooling is present. This is a hygiene gap for a package with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
platformsh/client Version ^0.11.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.