The package has a declared MIT license, tests, and a small dependency footprint. Its source appears stale and the repository README describes a different starter project, so pinning it carries substantial maintenance and identity risk.
38%
Total Score
50
100
63
50
This package has only one release, published in February 2018, with no releases in the past 12 months. That is strong evidence of abandonment for a dependency released over eight years ago.
The repository had zero commits and zero active maintainers during the last three months. Combined with the single-release history, this indicates no observable current maintenance.
The repository name does not match the package name and its README does not mention the package; instead, the README describes a Bolt extension starter. This raises a meaningful concern that the linked source may not represent this release.
The project uses Composer, providing ordinary build tooling, but no security-scanning tool was detected. This is a modest transparency and hygiene gap rather than a standalone adoption blocker.
The linked repository is not archived, but it was last pushed in February 2018, consistent with the package's long inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bolt/bolt Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.