The artifact has a readable but minimal README, no install hooks, and a small, inspectable file set. Its licensing is unclear and the package has had no release in over six years, so adoption should be avoided.
15%
Total Score
100
30
100
Packagist marks the entire package as abandoned, with no replacement listed. This is a severe dependency risk because future maintenance and support are not expected.
Only two releases were published, both in October 2019, and there have been no releases in over six years. The long release gap strongly indicates abandonment.
No declared license, license file, or detected license is present. This creates a material legal and adoption risk for downstream projects.
A README is present, but it is only 21 characters long and provides little consumer guidance. The absence of tests and a changelog is not treated as a gap for a published package artifact.
The latest version is v0.0.2 and is not a stable major release, which provides little maturity evidence. The old release history reinforces that this is not an actively evolving dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sabre/xml Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.