The README and license make the package easier to evaluate, and installation has no lifecycle scripts. Its small dependency set and repository reference add transparency, but these benefits do not offset the lack of current project activity.
40%
Total Score
50
100
80
75
The package has had only 2 releases, with none in the last 12 months; its latest release was published in October 2016. This is strong evidence of abandonment for a dependency still being considered today.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance capacity.
There were no new or closed issues or pull requests in the last month, with 1 issue still open. This reinforces the lack of recent project activity, although it is weaker evidence than the absent commits and releases.
The repository has no security policy or documented security-reporting path. This is a transparency and response-readiness gap, though the package's long inactivity is the larger concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
msp/common Version * | — | — |
magento/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.