The package has a clear MIT declaration, extensive tests, and a substantial README. Its small dependency set and clean package structure reduce adoption friction, but they do not provide current maintenance coverage.
45%
Total Score
50
100
71
83
The latest release was published about nine years ago, with no releases in the last 12 months. This strongly suggests abandonment for a deployment package that may need ongoing compatibility and fixes.
The package has one registry maintainer. A single maintainer is a limited support base, and the concern is amplified by the long absence of releases and repository activity.
Composer and Make are used for project tooling, showing basic build structure. No security scanning tools are present, which is a minor hygiene gap but not decisive compared with the maintenance evidence.
The repository is not archived, but it was last pushed about nine years ago. Its accessible status is mildly reassuring, while the prolonged lack of activity remains a maintenance concern.
The repository has no security policy. This limits guidance for reporting vulnerabilities, but it is a secondary concern rather than evidence that the package is unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
naneau/semver Version dev-master#c771ad1e6c89064c0a4fa714979639dc3649d6c8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.