The package is well documented and tested, with a clear license and matching organization-owned repository. Its dependency and security hygiene are acceptable, but the project shows no release or commit activity for about 10 years, making future fixes unlikely.
42%
Total Score
63
100
78
75
Only two releases are recorded, with the latest about 10 years ago and none in the last 12 months. This strongly indicates abandonment risk, despite the package not being deprecated.
The repository had no commits and no active maintainers in the last three months, consistent with the long release gap. There is no provided evidence of ongoing maintenance to compensate for this.
There are no open issues or pull requests and no recent issue or pull-request activity. The lack of unresolved work is positive, but in combination with zero commits it is also consistent with a dormant project.
The repository has zero stars and forks and one watcher, offering little supporting evidence of adoption. Popularity is only supporting evidence, so this does not drive the score by itself.
Composer is used for builds, which fits the package ecosystem. No security scanning tools are present, leaving a modest security-process gap alongside the much more significant maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ganbarodigital/php-http-status Version ^2.0 | — | — |
ganbarodigital/php-mv-defensive Version ^1.2016052101 | — | — |
ganbarodigital/php-mv-di-containers Version ^1.2016050901 | — | — |
ganbarodigital/php-the-missing-bits Version ^1.2 | — | — |
ganbarodigital/php-mv-exception-helpers Version ^v1.2016061902 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.