The source repository is still active, with 17 commits in the last three months, but all came from one contributor. It includes a license, README, changelog, and tests in the repository, though it has no security policy.
20%
Total Score
83
100
75
83
Packagist marks the entire package as abandoned, not merely this release, and identifies a replacement package. That is a severe adoption risk even though the repository remains active.
The package has had no registry releases in the last 12 months, and its latest release is from February 2021. Recent repository activity partly offsets abandonment concerns but does not restore release freshness.
All 17 recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization backing provides some handoff capacity but does not remove the concentration risk.
The linked repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/engine Version ^0.7.13 | — | — |
pop-schema/schema-commons Version ^0.7.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.