The repository includes tests, a matching MIT license, and no install-time scripts, which support basic transparency. But seven years without a release or commit activity makes this version a risky long-term dependency.
42%
Total Score
0
71
75
The package is about seven years old, with no releases in the last 12 months. Its 19 releases show past activity but do not offset the prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating likely abandonment.
The repository has zero stars, forks, and watchers. This is only supporting evidence and does not independently establish abandonment, but it provides no additional maturity signal.
Composer is used for the build, but no security scanning tools are configured. The build tooling is appropriate, while the missing scanning reduces security-process transparency.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency weakness, though less significant than the inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
greenter/core Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.