The package has a clear README, tests, and organization-backed source repository. Its release record is minimal and the source has had no commits in the last three months; use the native extension instead when possible.
12%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe maintenance and adoption warning for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. This supports the abandonment concern rather than merely reflecting a quiet stable project.
The linked repository is archived, indicating the project is no longer intended for active development. Its last push was on March 1, 2026, which does not offset the archived state.
The package has only one release, published over a year ago, and none in the last 12 months. That leaves little evidence of an established release or maintenance track record.
The single workflow was fully analyzed with no audit findings or untrusted execution paths, but all three action references are unpinned and the workflow has no top-level permissions block. This is a minor reproducibility and hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pocketmine/binaryutils Version ~0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.