The published artifact is compact and understandable, with tests, an MIT license, and no install-time script. Its source repository matches the package and is not archived, but these positives do not offset the lack of ongoing project support.
42%
Total Score
0
75
75
This is the only release, published about 11 years ago, with no releases in the last 12 months. That leaves compatibility and maintenance concerns unresolved despite the package being stable rather than prerelease.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package having been untouched since 2015. This is strong evidence of abandonment risk.
Composer is used for project builds, but no security scanning tooling is reported. This is a minor hygiene limitation, not evidence of unsafe behavior by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. For an otherwise inactive project, that modestly worsens maintenance transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mishal/iless Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.