The release has clear documentation, tests, and recent compatibility work, but maintenance is concentrated in one contributor with only one commit in three months. Its workflow also uses two unpinned actions, and the registry abandonment status warrants checking the replacement before adoption.
62%
Total Score
50
100
86
75
The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the concentrated contributor activity.
Packagist marks the entire package as abandoned, although the assessed version was released recently and the listed replacement is the same package name. This is a meaningful adoption warning but not evidence that this release is unfit by itself.
One contributor made 100% of the recent commits. Because the repository owner is an individual rather than an organization, this concentration increases handoff and abandonment risk.
Only one commit was recorded in the last three months, showing some recent maintenance but a thin activity level. This limits confidence in sustained support.
The repository has five stars and one fork, indicating limited external adoption. Popularity is supporting evidence rather than a verdict, but it provides little additional confidence here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jord-jd/do-file-cache-psr-6 Version ^3.0||^4.0 | — | — |
jord-jd/php-wikitext-parser Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.