Risky to adopt: the latest release was published in December 2014, with no releases or repository commits in the last 12 months. It has a matching repository, tests, a README, and an MIT license, but the long-standing inactivity makes abandonment a serious concern.
38%
Total Score
0
75
83
The package has only three releases, all concentrated around December 2014, and none in the last 12 months. This long period without a release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's decade-long release inactivity. No provided activity signal compensates for this lack of maintenance.
Composer is used as a build tool, but no security scanning tool is present. The missing scanning is a modest transparency gap, secondary to the much more significant maintenance inactivity.
The linked repository is not marked archived, which avoids the strongest repository-level abandonment signal, but its last push was still in December 2014. The non-archived status only partly offsets the observed inactivity.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a minor transparency weakness for a package that has otherwise been inactive for many years.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opine/db Version ~2.0 | — | — |
opine/bundle Version ~2.0 | — | — |
opine/helper Version ~2.0 | — | — |
opine/layout Version ~2.0 | — | — |
opine/container Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.