The package includes a clear MIT license, README, lightweight dependencies, and no install-time scripts. Missing security policy and scanning reduce transparency, while the repository still matches the package.
43%
Total Score
100
72
83
The latest release was published in June 2017, and there have been no releases in about 9 years. This is strong evidence of abandonment for a framework package.
The repository has 0 stars and 0 forks, with only 1 watcher, providing little evidence of community adoption or external maintenance support.
Composer is used for builds, but no security scanning tools are configured. That is a transparency and maintenance gap, though it is less serious than the long inactivity.
The repository is not archived, which leaves the project technically open for maintenance, but its last push was also in June 2017 and does not offset the stale release history.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This compounds the limited maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
muramoya/ktrlib Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.