The MIT license, readable package, and single runtime dependency make the code easy to inspect. Its repository is not archived, though it has no security policy or scanning.
38%
Total Score
0
100
67
50
The latest release was published in August 2015, with no releases in more than 11 years despite 35 historical releases. This indicates severe abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, and its last push was in August 2015. This confirms that maintenance has stopped rather than merely slowing.
The repository has zero stars and one fork. Popularity is only supporting evidence, but these counts provide little external evidence of active adoption or community maintenance.
Composer is used for the build, but no security-scanning tooling is present. That is a modest transparency and maintenance concern, especially for an otherwise inactive project.
The repository has no security policy. This limits guidance for reporting vulnerabilities, although the small package scope reduces the significance compared with its abandonment risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
krisanalfa/bono-blade Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.