The repository is small, has no security policy or scanning, and its workflow leaves all three actions unpinned. A clear license, useful README, stable release, and organization backing provide some protection against abandonment.
52%
Total Score
50
100
78
50
The latest release was nearly three years ago, with no releases in the last 12 months. That strongly suggests maintenance has stopped, despite 12 releases establishing some prior history.
There were no commits and no active maintainers in the last three months, consistent with the long release gap. This is substantial evidence of current abandonment risk.
A post-install-cmd script runs during installation, adding supply-chain and reproducibility surface beyond ordinary file installation. No provided signal shows that this script is harmless or necessary.
There were no new or closed issues or pull requests in the last month, and no open work remains visible. Combined with the absent commits, this provides little evidence of active maintenance.
The repository has no stars and only two forks. Low popularity is supporting evidence of a small user base, but it is not independently decisive for a specialized package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drop-in-gaming/carbonphp Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.