The package is small, clearly documented, and has no install-time scripts. Its source and release history have been inactive for about 11 years, with no tests or security scanning to support ongoing maintenance.
42%
Total Score
0
75
50
The latest release was published about 11 years ago, and there were no releases in the preceding 12 months. This strongly raises abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and indicating no current maintenance activity.
Composer is used for builds, but the repository has no security-scanning tools. This is a maintenance and assurance gap, though it is less significant than the lack of recent development.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This adds a transparency gap for a library that handles server communication.
No GitHub Actions workflows were present, so there are no workflow vulnerabilities to report; this also provides no automated maintenance or release assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
heydon/uarray Version 1.0.*@dev | — | — |
heydon/redback Version 1.0.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.