The repository has only three recent commits from one contributor, and the tiny artifact is explicitly a migration shim. The Apache-2.0 license and absence of install scripts reduce friction but do not change the recommendation.
15%
Total Score
67
50
67
100
Packagist marks the entire package abandoned and identifies pushinbr/pam-contracts as the replacement, making this release unsuitable for new dependencies.
The package has one runtime dependency, pushinbr/pam-contracts, confirming that it primarily forwards consumers to the replacement rather than providing an independent implementation.
One contributor performed 100% of the three recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown.
Only three commits were recorded in the last three months, all from one active maintainer, which provides little evidence of ongoing development for this package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pushinbr/pam-contracts Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.