The README and source tree are substantial, and installation runs no lifecycle scripts. However, the package has had no releases or repository activity for over 11 years, with no security scanning or policy.
42%
Total Score
50
100
75
83
The latest release was published in June 2015, and there were no releases in the last 12 months. This long release gap is a strong abandonment concern despite the package having an established release history.
The repository recorded zero commits and zero active maintainers in the last 3 months, while its last push was in June 2015. That indicates maintenance has effectively stopped.
The artifact includes a license file and the repository also has one, so licensing is present. However, the manifest declares BSD-4-Clause while the detected file is BSD-3-Clause, creating a material license mismatch.
The repository uses Make and Composer, indicating basic build tooling. It has no reported security scanning, which is a modest transparency and maintenance gap for an old project.
The repository has no security policy. This is a transparency gap, though the package's long inactivity is the more significant concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ethnam/getopt Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.