The README, matching repository, and lack of install scripts provide useful transparency. However, releases and repository activity stopped in December 2016, while the project has no security scanning and only a nonstandard license declaration without a license file.
32%
Total Score
0
69
75
The package is over 9 years old but has only two releases, both published within minutes on December 18, 2016, and none in the last 12 months. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months, consistent with the release history showing no releases for years. This materially increases abandonment risk.
The manifest declares “MITS,” but no license file was found in the package or repository and the detected license is null. The release therefore has weaker licensing transparency than the declaration alone suggests.
Composer is used for builds, but no security scanning tooling is present. For a PHP application framework, that is a meaningful maintenance and transparency gap, though it is not conclusive by itself.
The repository has no security policy. This limits transparency about vulnerability reporting and response, adding to the concerns raised by the long period of inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
legionlab/rest-kernel Version ^0.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.