The repository matches the package, the MIT license is declared, and the small dependency set is understandable. Its alpha status, minimal project activity, and lack of security tooling make long-term maintenance uncertain.
38%
Total Score
50
67
50
Only two releases exist, with none in the last 12 months; the latest release was published over 10 years ago. This is strong evidence of abandonment risk.
The repository recorded no commits or active maintainers in the last three months, and its last push was over 10 years ago. This strongly weakens confidence in ongoing maintenance.
There are three open pull requests but no new or closed issues or merged pull requests in the last month, suggesting that visible project activity is stalled.
Composer is used as the build tool, but no security scanning tools are present. For a small package this is a modest transparency and maintenance gap, not a severe risk.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. The package's age and inactivity make this gap more consequential.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/event Version ~1 | — | — |
silverstripe/framework Version ~3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.