The small codebase has a clear README, an MIT license, and no install-time scripts. Its minimal adoption and lack of security scanning leave limited evidence of ongoing project care.
43%
Total Score
0
75
75
The latest release was about six years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite a reasonable earlier cadence.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and reducing confidence in ongoing maintenance.
The repository has 0 stars, 1 fork, and 2 watchers, providing little supporting evidence of community review or maintenance capacity. Low popularity alone is not decisive, but it reinforces the inactivity concern.
Composer is used for the build, which is appropriate for this package, but no security scanning tools are configured. That leaves a transparency and maintenance gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a modest transparency concern for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
box/spout Version ^3.1 | — | — |
fabpot/goutte Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.