The package has a focused 15-file tree, a matching repository, and no install-time scripts. Its single maintainer, missing license, and absent security policy leave limited visible support for future fixes.
28%
Total Score
25
100
75
83
Only two releases exist, with the latest published nearly 12 years ago and none in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance.
No license declaration or license file was detected in the package or repository, leaving the legal terms for dependency use unclear.
The registry lists one maintainer. The repository is user-owned rather than organization-owned, so there is little visible maintainer redundancy if that person stops supporting it.
The repository has no security policy, reducing transparency about how vulnerability reports would be handled. This compounds the evidence of limited ongoing support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/nette Version >= 2.2.0 | — | — |
knplabs/gaufrette Version 0.2.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.