The BSD-3-Clause declaration, README, and dependency-light artifact offer some transparency. The repository does not identify the package in its README, and it has no security scanning or policy, leaving little evidence of current stewardship.
8%
Total Score
0
100
42
75
Packagist marks the package as abandoned at package scope, with no replacement provided. That is a direct warning against taking a new dependency on this release.
The package has only three releases, all concentrated in August 2014, with no releases in the last 12 months. This is consistent with a long-abandoned dependency.
There were zero commits and zero active maintainers in the last three months. Together with the archived repository, this provides no evidence of ongoing maintenance.
The linked repository is archived and was last pushed about 12 years ago. Archived source strongly indicates that maintenance and issue response are no longer expected.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, it reduces confidence that the linked source clearly represents this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kohana/core Version >=3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.