The repository includes tests, a README, and an MIT license, while installation scripts are absent and the package is not deprecated or archived. Its only release was about 12 years ago, with no recent commits or issue activity, leaving maintenance and compatibility uncertain.
38%
Total Score
25
79
75
This package has only one release, published about 12 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency.
The repository had zero commits and zero active maintainers in the last three months; its last push was in 2017. This provides no evidence of current maintenance capacity.
There were no new or closed issues or pull requests in the last month, while two issues remain open. This reinforces the lack of recent project activity.
Composer is used for builds, which is appropriate for this package, but no security scanning tools are configured. The missing scanning is a modest hygiene gap rather than evidence of abandonment by itself.
The repository has no security policy. For an inactive library, this reduces transparency and leaves no documented path for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rych/bytesize Version 1.0.* | — | — |
davewid/peyote Version 0.7.* | — | — |
gavroche/browser Version 2.2.* | — | — |
swiftmailer/swiftmailer Version 5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.