The package has a clear README, tests, release notes, an MIT license, and read-only workflow permissions. Its pre-1.0 status and three unpinned workflow actions offer little reassurance for future maintenance.
18%
Total Score
50
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The linked source repository is archived, which strongly indicates that active maintenance has ended even though it was pushed about 7 months ago.
The latest release was published about 2 years and 6 months ago, with no releases in the last 12 months. The package has a prior release history, but the current gap is substantial for a dependency.
The repository recorded no commits and no active maintainers in the last 3 months. This reinforces the abandonment concern shown by the archived repository and abandoned registry status.
Version 0.7.0 is not a stable major release, so API compatibility may require more care. This matters more because there is no current maintenance evidence to support future fixes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lstrojny/fxmlrpc Version ^0.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.