The replacement package is the better long-term choice for new projects. Active commits and a clear license help, but workflow pinning and repository identity concerns add avoidable risk.
35%
Total Score
75
100
71
67
Packagist marks the entire package as abandoned and names jasonmccreary/double as its replacement, so this release should not be a new dependency despite recent activity.
Three contributors were active, but one made about 93% of commits, leaving maintenance heavily concentrated in a single person.
The repository name does not match this package and its README does not mention it; the README instead documents the replacement package, suggesting this package may be an abandoned or transitional name.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.