The package is clearly identified, licensed, and documented, with repository tests and a stable version. Its automation has credential-handling and pinning weaknesses, adding maintenance risk beyond the package’s long-standing inactivity.
10%
Total Score
0
57
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-level abandonment is a severe warning for taking a new dependency.
The package has had no release in over six years and no releases in the last 12 months. The short historical release cadence does not compensate for the prolonged inactivity.
The repository recorded no commits and no active maintainers in the last three months. Together with its archived state, this confirms that current maintenance capacity is absent.
The linked repository is archived and was last pushed over four years ago, indicating the project is no longer maintained. This independently creates substantial abandonment risk.
The repository has no security policy. This reduces vulnerability-reporting transparency, and there is no provided compensating process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.