Risky to adopt because Packagist marks the package abandoned and names a replacement. It is actively released and backed by a matching, non-archived repository, but new projects should use the replacement package instead.
32%
Total Score
50
100
78
83
Packagist marks the entire package as abandoned and points to bladewindui/checkbox as its replacement. This is a direct maintenance and adoption risk for a new dependency.
A single registry publishing maintainer is consistent with this user-owned repository, but it leaves little visible publishing redundancy and increases continuity risk alongside the abandoned status.
The repository has zero stars, forks, and watchers, providing no community support signal. Popularity is only supporting evidence, so this does not independently establish that the package is unsafe.
Composer is used as the build tool, but no security scanning tools are present. The tooling is appropriate for the ecosystem, while the missing security scanning is a modest hygiene concern.
The repository has no security policy. This is a transparency gap, although the package is small and the lack of a policy is less decisive than its explicit registry abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mkocansey/bladewind-core Version ^4.4 | — | — |
mkocansey/bladewind-icon Version ^4.4 | — | — |
mkocansey/bladewind-script Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.