The package includes tests, a changelog, and a clear Apache-2.0 license. Its single release and zero recent commits leave consumers dependent on code that appears abandoned.
34%
Total Score
0
67
50
This package has had only one release, on February 24, 2014, and none in the last 12 months. That is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old release history, this indicates abandonment risk.
Composer and Phing provide build tooling, but no security-scanning tool is present. This is a modest hygiene gap rather than evidence of unsafe behavior on its own.
The repository is not formally archived, which is a small positive, but its last push was on August 27, 2014 and does not offset the lack of current activity.
The repository has no security policy. This is a transparency gap, though it is less significant than the package's much stronger abandonment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
qranio/azure-sdk-pear-deps Version v1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.