Licensing is explicit, the artifact is compact, and it has no install-time scripts. The repository could not be found, so maintenance and provenance remain unverifiable; prefer a maintained replacement.
12%
Total Score
50
50
50
100
Packagist marks the entire package as abandoned, with no replacement package provided. This is a severe adoption risk because the release is explicitly withdrawn from active support.
The package has had no release in nearly seven years, despite eight releases overall. That long period without a new release strongly indicates abandonment for a dependency.
The package has three runtime dependencies, including two related Flood components, and no development dependencies. The modest profile is manageable, though its dependency chain may share the same aging project.
Two registry accounts have publish access, but this is administrative metadata and does not demonstrate active maintenance. The release history provides stronger evidence of the project's current state.
Version 0.3.4 is not a prerelease, which avoids one stability concern, but it remains an old pre-1.0 line with no recent releases to demonstrate ongoing support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flood/component-cache Version ^0.1 | — | — |
flood/component-route Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.