Its dependency list is small, but the release remains on the 0.x line and only one publisher account is recorded. The repository could not be found, leaving current maintenance and provenance unverified.
15%
Total Score
100
17
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry explicitly signals that ongoing support should not be expected.
The latest release was published in October 2014, and there have been no releases in the last 12 months despite the package being about 13 years old. This strongly indicates abandonment.
The latest version is still v0.3.7 rather than a stable major release. That is a maturity concern, although the package's long inactivity and abandonment status are more decisive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version 4.1.* | — | — |
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.