Usable with caveats: the package is stable, licensed, backed by an organization, and has a matching source repository with release notes. However, it has had no release or repository commits for about two years, and the repository lacks a security policy and README reference to the package.
64%
Total Score
67
100
81
88
The package has 11 releases since February 2017, but its latest release was about 2 years ago and there were no releases in the last 12 months. This is a meaningful maintenance concern for a dependency, though not evidence of abandonment by itself.
There were no commits and no active maintainers in the last 3 months; combined with the roughly 2-year release gap, this points to a presently inactive project.
There is one open issue and no issue or pull-request activity in the last month, offering no recent evidence of active support.
The repository name matches the package, so it does not appear to be piggy-backing on an unrelated project. However, the README does not mention the package, which is a modest transparency gap.
Composer build tooling is present, but no security scanning tooling is configured. For this small package that is a hygiene gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
level-level/clarkson-core Version ^1 | ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.