It has a clear README, release notes, repository tests, and an MIT license. The organization-backed project is transparently linked to the package, but the available maintenance evidence leaves no dependable path for ongoing support.
10%
Total Score
50
50
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk rather than a cosmetic metadata gap.
The package has 56 releases since 2017, but none in the last 12 months and its latest release was in April 2022. Its earlier regular cadence does not compensate for the prolonged release gap.
There were no commits and no active maintainers in the last three months, consistent with the repository being archived and providing no current maintenance capacity.
The linked HHVM repository is archived and was last pushed in June 2022, indicating the source is no longer maintained through its primary project.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. Both actions are unpinned, which is a modest reproducibility concern but not enough to change the overall severe maintenance verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hhvm/hhast Version ^4.158 | — | — |
hhvm/type-assert Version ^3.2|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.