The package includes a clear README, a real source repository, and a small runtime dependency set. It has had no release in about two years, no recent commits, and a GPL-3.0 file despite a proprietary declaration.
56%
Total Score
50
100
79
75
The manifest declares a proprietary license, but the artifact and repository contain a GPL-3.0 license file. This licensing mismatch needs clarification before adoption.
The package has 28 releases since January 2020, but none in the last 12 months; the latest release was about two years ago. Earlier release activity shows some history, but current maintenance appears stalled.
The repository recorded no commits and no active maintainers in the last three months. With no recent registry releases, this is meaningful abandonment risk.
The repository uses Composer for builds, which fits the package ecosystem, but it has no security scanning tools. The missing scanning is a minor hygiene gap rather than a decisive risk.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less serious than the maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
binarytorch/larecipe Version ^2.2 | — | — |
binarytorch/larecipe-swagger Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.