Risky to depend on: the package has had no release in nearly five years and provides only a three-file artifact with a placeholder README. No source repository is declared, leaving maintenance and provenance difficult to verify, despite a stable version, declared license, and no install scripts.
38%
Total Score
100
70
75
The package was released three times around October 2021, but has had no release in nearly five years. That prolonged inactivity is a meaningful abandonment risk for a dependency.
The artifact contains only .gitignore, README.md, and composer.json, with no apparent source files or tests. This unusually thin package structure makes it difficult to verify what consumers receive.
A README is present, but its 565 characters are an unfilled setup template rather than usable integration or maintenance documentation. The absence of tests and a changelog in the published artifact is normal packaging practice and is not penalized.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
manaf/test-repo-reviews Version 4.1.0 | — | — |
manaf/test-repo-messaging Version 4.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.