The MIT license and matching repository make the package transparent enough to inspect, and its README explains setup. The very small project footprint and absent security policy provide little reassurance for a package that has not visibly evolved.
45%
Total Score
50
63
75
The package has only four releases, all clustered in May 2022, with no releases in the following four years. That strongly raises abandonment risk for a dependency still at version 0.0.4.
One registry publisher account is consistent with a small user-owned project, but there is no broader maintainer base shown to provide resilience if that owner stops maintaining it.
The repository has one star, no forks, and one watcher. Popularity is not required for health, but these counts provide little supporting evidence of community use or review.
Composer is used as the build tool, but no security-scanning tools are present. The missing scanning support is a modest hygiene concern alongside the stale project activity.
The repository is not archived, which avoids an outright abandonment marker, but its last push was also in May 2022 and does not offset the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
apache/thrift Version ^0.16.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.