Its dependency surface is small and the repository is not archived. Composer tooling is present, but security coverage and consumer documentation are thin.
30%
Total Score
0
100
58
75
The package was released only twice, with no releases in roughly 10 years. This strongly indicates abandonment risk for a dependency.
The repository has had no commits or active maintainers in the last 3 months, consistent with its last push roughly 10 years ago. That leaves little evidence of ongoing maintenance.
Neither the package metadata nor the available repository contains a recognized license or license file. This creates a real adoption and redistribution concern.
The published artifact and repository each contain only composer.json, providing very little visible implementation or project documentation. This reduces transparency and makes the package difficult to evaluate.
The package has no README, while tests and a changelog are normal omissions from published artifacts; the missing README still hurts consumer documentation for a Packagist dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mazhalai/test-package3 Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.