It has no install-time scripts and uses a straightforward Composer build, reducing execution and packaging concerns. Organization ownership and a non-archived repository provide some continuity, but this remains an early 0.x dependency.
42%
Total Score
0
43
75
No declared license, license file, or repository license file was found, leaving developers without clear permission to use or redistribute the package.
The package has had no release in about two years and no releases in the last 12 months, despite seven releases clustered near its launch; this is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and materially increasing maintenance risk.
The package has no README, tests, or changelog, which weakens consumer guidance and project transparency. The exact version does have a GitHub release, partially compensating for the missing changelog.
The repository name does not match the package name, and no README package mention was available. This may reflect a related repository or monorepo structure, but package ownership is less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swow/swow Version v1.5.2 | — | — |
geardev/swow Version ^0.1 | — | — |
geardev/processes Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.