Usable with caveats: the package is licensed, documented, tested, and not deprecated, but it appears effectively unmaintained, with no release or repository commit activity for about two years and six months. Its small user base and lack of a security policy add further maintenance risk.
62%
Total Score
25
81
88
There were zero commits and zero active maintainers in the last three months, consistent with the last push being about two years and six months ago. This is the strongest concern because fixes and compatibility updates may not arrive.
The linked repository is owned by an individual rather than an organization, so there is no demonstrated organizational continuity to compensate for the lack of recent activity.
The package has seven releases, but none in the last 12 months; its latest release was about two years and six months ago. This strongly lowers confidence in ongoing maintenance despite the initially rapid release cadence.
The repository has one star, zero forks, and one watcher. Popularity is only supporting evidence, but these very low figures provide little external evidence of adoption or review.
The repository uses Composer, but it reports no security-scanning tools. Build tooling supports basic project maintenance, while the missing security automation is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
darling/roady-routes Version ^1.0 | — | — |
darling/php-web-paths Version ^1.0 | — | — |
darling/php-text-types Version ^1.1 | — | — |
darling/php-darling-dev-tools Version ^1.0 | — | — |
darling/php-file-system-paths Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.