The package has tests, a matching source repository, and a clear MIT license. Its minimal release history and absent security policy provide little evidence of ongoing care.
34%
Total Score
25
100
63
83
Only two releases were published, both within minutes on September 22, 2016, with no releases in the last ten years. This is strong evidence of an abandoned or unfinished dependency.
There were no commits and no active maintainers in the last three months, consistent with the last push being about ten years ago. This materially raises abandonment risk.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This provides limited backing context without proving a maintenance problem.
The repository has zero stars and zero forks, with one watcher. Popularity is only supporting evidence, but these values provide no external sign of active adoption.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dez-configuration Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.