The repository is small and has no commits in the last three months, with only two releases recorded. Its MIT license, tests, documentation, and matching source repository provide useful transparency, but do not offset the package-level withdrawal.
38%
Total Score
50
100
75
75
Packagist marks the entire package as abandoned and names nexus-scholar/graph-core as the replacement. Package-level deprecation is a severe adoption concern even though this specific release is not individually withdrawn.
The package has only two releases, both within about three days, despite being about 359 days old. That short history provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens evidence of ongoing maintenance, although the repository was pushed more recently than that measurement window.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The linked repository has no security policy. For a dependency that may process application data, the lack of a documented vulnerability-reporting path reduces maintenance transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.