The short README and lack of tests limit confidence for consumers, though the package is easy to identify and has no install-time scripts. Its low adoption and absent security policy add uncertainty for long-term maintenance.
42%
Total Score
50
67
75
This package has only one release, published about 5 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
There were no new or closed issues or pull requests in the last month, and no open work is visible. With the old release date, this supports a concern about inactive maintenance.
The repository has 0 stars, 0 forks, and 1 watcher, providing little supporting evidence of community adoption or external maintenance capacity.
The repository is not archived, which is reassuring, but it was last pushed about 5 years ago and does not offset the lack of subsequent releases.
No security policy was found in the repository. This is a transparency gap, though it is secondary to the much stronger evidence about release and maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bower-asset/zxcvbn Version ~4.4 | — | — |
bjeavons/zxcvbn-php Version ~0.3 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.