The package includes a README, tests, and a repository that clearly matches its name and organization. It has been deprecated, archived, and inactive for over four years, while its declared EUPL-1.1 license differs from the detected EPL-1.0 file.
10%
Total Score
50
42
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry explicitly signals that maintenance has ended.
The package has 40 releases but none in the last 12 months; its latest registry release was in May 2022. The historical release count does not compensate for more than four years without a release.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the archived and abandoned status.
The linked repository is archived, and its last push was over four years ago. Archival strongly indicates that new fixes and maintenance should not be expected.
A license file is present, but the manifest declares EUPL-1.1 while the artifact file is detected as EPL-1.0. This mismatch creates licensing uncertainty despite the presence of repository and artifact license files.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.