Risky to adopt: the package has had no registry release in more than six years and no repository commits in about five years. It is not deprecated or archived and has a license and usable README, but the long inactivity makes abandonment a substantial concern.
42%
Total Score
0
75
75
The latest release was published on June 2, 2020, and there have been no releases in the last 12 months. This long release gap is a strong indication of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being about five years ago. The repository is not archived, but it shows no recent maintenance activity.
The repository has only two stars, zero forks, and zero watchers. Low popularity is supporting evidence of limited adoption, not a decisive health verdict by itself.
Composer is used as the build tool, but no security scanning tools are present. This is a modest transparency and maintenance gap, though the absence of scanning alone is less serious than the prolonged inactivity.
The repository has no security policy. This weakens vulnerability-reporting transparency, but it is secondary to the more substantial abandonment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.