The source includes tests, a matching MIT license, and a release note for this version. Its tiny dependency profile and organization backing help, but the long-maintenance gap makes future compatibility uncertain.
42%
Total Score
50
75
75
The latest release was nearly 9 years ago, with no releases in the last 12 months; this is strong evidence of abandonment risk for a dependency.
The repository had no commits in the last 3 months and was last pushed about 7 years ago, indicating that maintenance has effectively stopped.
Composer is used as a build tool, but no security scanning tools were detected; this is a minor repository hygiene gap rather than a standalone dependency-blocking risk.
No repository security policy was found, reducing transparency for reporting vulnerabilities, although this is secondary to the much larger maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pug-php/pug Version ^2.0 || ^3.0 | — | — |
nodejs-php-fallback/stylus Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.