Don’t rely on this release as a dependency without a fallback: Packagist marks the package as abandoned, and the source repo is archived with no recent maintenance. The artifact also lacks tests and a changelog, making upgrades and fixes harder to verify.
28%
Total Score
50
100
50
83
The registry explicitly marks the package as deprecated via packagist_abandoned for the package overall, not just this release.
The package hasn’t had a release in the last 12 months and the latest published release is from years ago, which is a strong sign of maintenance slowdown or abandonment.
The linked GitHub repository is marked archived and last pushed years ago, indicating it is no longer actively maintained.
Only one maintainer has publish access, which can be fine for small projects but raises bus-factor risk when combined with lack of recent maintenance.
The release includes a readme but has no tests and no changelog, so there’s little verification history or documented change trail for this version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nodes/api Version ^2.0 | — | — |
nodes/core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.