The package is clearly licensed and has a matching source repository, but consumer documentation is absent. Its minimal artifact and lack of security policy add transparency concerns for a library dependency.
32%
Total Score
50
71
67
This package has only one release, published nearly nine years ago, with no releases in the last 12 months. That strongly suggests abandonment risk for a library dependency.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the release history showing no activity since 2017.
The artifact and repository each contain only four files, including one source file and no tests or README. This may fit a minimal adapter, but it provides little visible maintenance or usage context.
The package has a changelog and GitHub release, but no README and no tests. The missing README reduces consumer guidance, while the absent tests weaken confidence in ongoing maintenance.
Composer is used for builds, but no security scanning tooling is present. For an otherwise inactive project, this is a modest transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/dav Version ~3.1 | — | — |
league/flysystem Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.