The small, focused codebase is documented and tested, with a clear MIT license. Its missing security policy and install-time Composer hooks warrant extra care when integrating it into automated builds.
38%
Total Score
0
80
50
The latest release was published in January 2013, and there have been no releases in the last 12 months despite the package being over 13 years old. This is strong evidence of abandonment risk, with no newer release to compensate for the age.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. No provided signal shows current maintenance capacity.
The package registers post-install and post-update Composer scripts, which are expected for its documented tag-generation purpose but execute package code during dependency operations. This adds integration and review risk without indicating maliciousness.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a modest transparency gap, especially for a dependency installed into developer environments.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.