The package includes tests, a substantial README, a clear license, and a small runtime dependency set. Its single-owner project has had no recorded release or commit activity since 2014, so maintenance and compatibility are uncertain.
38%
Total Score
25
100
75
75
The latest release was in July 2014, with no releases in the past 12 months and only three releases overall. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap. No newer activity is provided to offset this concern.
Only one registry publishing maintainer is listed, which limits visible continuity if that maintainer stops supporting the package. The repository is user-owned rather than organization-backed.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tools are present. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. For a small, inactive package this adds to the maintenance concern, though it is not independently severe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
florianwolters/component-core-hashcode Version >=0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.