Risky to adopt: the package has had no release or repository activity for over seven years, and it provides no license or security policy. It is not deprecated or archived, and its tests and matching source repository offer some transparency, but the maintenance gap is a serious liability.
42%
Total Score
50
100
75
50
The latest release was published in May 2019, with no releases in the last 12 months. A gap of over seven years is strong evidence of abandonment risk despite the package having eight historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus and indicating no observable current maintenance capacity.
No declared license or license file was found in the package or repository, leaving the legal terms for using this dependency unclear.
Composer is used as the build tool, which supports reproducible package handling, but no security-scanning tools are configured. This modestly reduces maintenance transparency.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although it is less serious than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
anomaly/blocks-module Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.