The package includes a real repository test suite, matching MIT licensing, and release notes for this version. Its release and commit activity stopped over nine years ago, while four issues remain open; pin 0.1.2 only after compatibility testing.
40%
Total Score
25
64
50
The latest release was published over nine years ago, with no releases in the last 12 months and only three releases overall. This strongly raises abandonment and compatibility risk.
There were no commits and no active maintainers during the measured three-month period. Alongside the old last-push date, this supports a substantial abandonment concern.
Four issues remain open, with no new or closed issues and no pull-request activity in the last month. This adds evidence that outstanding maintenance work is not being handled.
The repository uses Composer, which fits the package ecosystem, but no security-scanning tools were detected. That is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository is not archived, which is a meaningful counterweight to the inactivity concerns. However, it was last pushed over nine years ago, so it does not show active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.