The MIT license, small dependency set, matching repository, and organization backing provide useful transparency. However, the project has no tests or security scanning and has not received a release or commit in more than 9 years, so maintenance risk is substantial.
42%
Total Score
50
75
50
The latest release was on February 27, 2017, with no releases in the last 12 months and only two releases overall. This is strong evidence of an abandoned or frozen project, although the stable 1.1.0 version may still be usable if its dependencies remain compatible.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. No provided maintenance signal compensates for this lack of recent activity.
The repository uses Composer, which supports reproducible project builds, but it has no security scanning tools. The missing scanning is a maintenance and hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This matters more for a library with no recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fdevs/geo Version ~1.0 | — | — |
fdevs/locale Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.