The MIT license, focused dependencies, and organization-backed repository support a clear ownership story. Tests and a changelog are present, but there is no security policy; pin this version and verify compatibility before adopting.
55%
Total Score
75
100
88
50
A pre-autoload-dump install-time script is present. This adds some installation complexity and execution surface, but the signal does not indicate a dangerous script by itself.
The package has 29 releases but none in the last 12 months, and version 1.0.28 was published about 6 years and 9 months ago. This long release silence materially raises abandonment risk.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this is strong evidence that active maintenance has stopped.
Composer is used as a build tool, supporting reproducible ecosystem-standard packaging. No security scanning tools were detected, which is a modest transparency gap but not a severe risk on its own.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package's tests, license, and non-archived repository provide some compensating project structure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drdplus/tables Version ^2.5 | — | — |
drdplus/calculator-skeleton Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.