Risky to adopt: this package has had no release or repository activity since February 2020, with no tests or security policy visible. Its MIT license, organization-backed repository, and matching source provide some transparency, but the long abandonment gap is a substantial liability.
35%
Total Score
67
69
100
The package has only four releases, all concentrated around February 2020, and none in the last 12 months; the latest release was over six years ago. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and indicating no recent maintenance capacity.
The package includes a README, but it is only 19 characters long, offering almost no guidance for consumers. Missing tests and a changelog in the published artifact are normal packaging practice, while the repository also reports no tests.
The repository has zero stars, forks, and watchers, providing no community adoption signal to compensate for the absence of recent maintenance.
Composer is used for builds, but no security scanning tools are present. This is a transparency and maintenance gap, though it is less serious than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
depa/depa-stdlib Version ^1.0 | — | — |
depa/depa-tooling Version ^1.0 | — | — |
laminas/laminas-db Version ^2.11 | — | — |
doctrine/collections Version ^1.6 | — | — |
laminas/laminas-diactoros Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.