The package is clearly licensed, documented, and linked to a matching repository. Its single maintainer and inactive project make it unsuitable as a normal application dependency; treat it as a test fixture instead.
15%
Total Score
50
100
63
75
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe adoption risk even though the release itself is not separately withdrawn.
This package has only one release, published 772 days ago, with no releases in the last 12 months. The absence of any subsequent release supports the abandonment concern.
A single registry maintainer provides little publishing redundancy. This is a concern alongside the package-wide deprecation and inactive repository, though it is not by itself severe.
The repository is owned by an individual account rather than an organization, so there is no observed organizational backing to compensate for the single maintainer and inactive project.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with the package's lack of releases. The repository is not archived, but there is no observed recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
foobar/foobar Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.