There has been no commit activity for three months, and the package has only one release. The missing security policy adds a transparency gap; use the named replacement instead.
8%
Total Score
0
50
50
Packagist marks the entire package as abandoned and names spiriitlabs/composer-update-report as its replacement. This is a direct indication that new projects should not depend on this package.
The repository recorded zero commits and zero active maintainers over the last three months. Together with the archived status, this provides strong evidence that maintenance has stopped.
The linked repository is archived, with its last push more than four months before collection. Archived source is a severe abandonment risk for a dependency.
The package has published only one release, with no subsequent releases during its 142-day lifetime. This is consistent with the abandonment indicators, though a young package can otherwise have a short history.
The repository has no security policy. That reduces transparency for reporting and handling issues, and no provided signal compensates for the gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.