The single-person project has no tests or security policy, which leaves maintenance and review capacity thin. The package is licensed, documented, and not deprecated or archived, but those positives do not offset its long inactivity.
35%
Total Score
50
75
75
The latest release was in November 2018, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk for a dependency that may need updates.
Only one registry maintainer is listed, and the project backing identifies an individual owner rather than an organization. That leaves limited visible continuity if the maintainer stops work.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but this provides little supporting evidence of community adoption or review.
Composer is used for builds, but no security-scanning tooling is present. This is a modest supply-chain hygiene gap rather than evidence that the release is unsafe.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported or handled. The package's small size limits the severity, but it remains a maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rollbar/rollbar Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.