Organizational ownership and a non-deprecated registry listing provide some continuity. The artifact's README appears unrelated to the package, and the repository has no security policy or security scanning.
45%
Total Score
67
61
75
The package has only two releases, both in October 2019, with no release in nearly seven years. That long absence of releases is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months; the repository's last push was nearly seven years ago. This is the clearest maintenance concern for the release.
The artifact includes a large README and release notes, but the captured README describes PclZip rather than this importer. The release notes document a small change, yet the unrelated README weakens consumer transparency.
The repository has zero stars and zero forks, with two watchers. Popularity is only supporting evidence, but these figures provide little additional evidence of community review or ongoing use.
Composer is used as a build tool, which supports reproducible project setup, but no security scanning tools were detected. The missing scanning is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.