It includes tests, release notes, and a repository that clearly matches the package. There is no recent project activity or security policy, leaving substantial abandonment risk despite the stable, non-deprecated release.
35%
Total Score
25
100
69
83
The package has had only three releases, all concentrated in December 2014, with no releases in the last 12 months. This is strong evidence of stagnation for a library dependency.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for nearly 12 years. This materially raises abandonment risk.
The repository is owned by an individual rather than an organization, so there is no provided evidence of broader project backing to compensate for the single-maintainer context and inactivity.
The repository has zero stars and forks and only one watcher, providing little evidence of community adoption or support. Popularity is supporting evidence, but this reinforces the maintenance concerns.
The repository uses Composer, but no security scanning tools were detected. The missing scanner is a transparency and hygiene gap, not proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opine/secret Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.