There have been no releases since October 2017 and no recent commits, with one registry maintainer and no security policy. The small dependency footprint and declared GPL license do not offset the abandonment risk.
15%
Total Score
25
100
50
83
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption warning even though it does not itself establish maliciousness.
The package has had no releases in more than eight years, despite being 3366 days old. This strongly indicates abandonment for a plugin that changes a web application's request endpoints.
The repository recorded zero commits and zero active maintainers in the last three months. This provides direct evidence that maintenance capacity has collapsed.
The linked repository is archived, and its last push was in April 2022. An archived source repository indicates the project is no longer actively maintained.
Only one account has registry publish access. That is a thin operational base, and there is no stronger observed maintenance activity to compensate for the concentration.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.