Biblioteca para cálculo do valor real do frete pelos correios.
48%
Total Score
unhealthy
No release since 2018 and no recent repository activity make this a risky dependency despite a clear license.
The package has had only two releases, with the latest published about 8 years and 7 months ago and none in the last 12 months. This is strong evidence of abandonment risk, although the stable 1.0.1 version may suit an unchanged niche use case.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this indicates that fixes and compatibility updates are unlikely to arrive promptly.
There were no new or closed issues or pull requests in the last month, while two issues and three pull requests remain open. This suggests limited current project attention, though the small project may receive little traffic.
Composer is used for the build, but no security scanning tool is configured. This is a maintenance and transparency gap, not a severe risk by itself.
The linked repository is not archived, so it remains formally available for maintenance. However, its last push was about 6 years and 11 months ago, which is consistent with the stale release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.