The package includes a clear README, repository tests, and an MIT license. Its organization-owned repository is not archived, but the long inactivity leaves compatibility and support uncertain.
45%
Total Score
50
75
50
The latest release was about seven years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, despite a previously regular median release interval of about 43 days.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and leaving current maintenance unverified.
Composer is used as a build tool, but no security-scanning tool is reported. This is a modest repository-hygiene gap rather than evidence of abandonment on its own.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This matters more because current maintenance activity is absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hhvm/hsl Version ^4.1 | — | — |
hhpack/getopt Version ^1.7 | — | — |
hhvm/type-assert Version ^3.3 | — | — |
hhvm/hhvm-autoload Version ^2.0 | — | — |
facebook/hack-codegen Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.