The package includes tests, a substantial README, and a source repository that matches its name. Its broad runtime dependency set and absent security scanning add maintenance burden.
35%
Total Score
25
50
75
83
This is the package's only release, published about 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that has not been maintained for years.
The package declares 15 runtime dependencies and no development dependencies, creating a comparatively broad compatibility and upkeep burden for an old release.
Eight issues remain open, while no issues or pull requests were opened or closed in the last month. This suggests unresolved maintenance needs and little ongoing support.
Two stars and no forks provide little evidence of a broad user or contributor base. Popularity is supporting evidence, but this small footprint increases bus-factor and support concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
curl/curl Version dev-master | — | — |
cebe/markdown Version 1.0.1 | — | — |
seld/jsonlint Version 1.3.1 | — | — |
smarty/smarty Version 3.1.21 | — | — |
endroid/qrcode Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.