The package has a clear README, a license, a small dependency set, and repository tests. Its source repository is archived and has had no commits for nearly five years, while the registry marks the package abandoned; pinning it would leave little maintenance support.
12%
Total Score
25
100
50
100
Packagist marks the entire package as abandoned, with no replacement specified. Package-level abandonment is a severe warning for a new dependency.
The package has 26 releases, but none in the last 12 months and its latest release was nearly five years ago. The earlier rapid release cadence does not compensate for the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms the maintenance gap shown by the archived status.
The linked repository is archived, and its last push was nearly five years ago. This strongly indicates the package is no longer maintained.
The repository belongs to an organization, which provides some ownership context. That backing does not compensate for the repository being archived and inactive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/translation Version ^0.8.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.