MIT licensing, tests, and organization backing improve transparency. The workflow also uses an unpinned container image, adding avoidable build risk.
38%
Total Score
50
71
The package has had no release in about six years, despite 23 historical releases; this strongly indicates abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and reinforcing abandonment risk.
There is no recent issue or pull-request activity, so there is no evidence of active maintenance or user support to offset the stale release history.
The project uses Composer for builds, but no security scanning tools were detected; this is a secondary hygiene gap rather than the main adoption concern.
Version v0.2.1 is still below 1.0, so compatibility expectations are weaker; the absence of prereleases is a small compensating sign.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
box/spout Version ^2.7 | — | — |
amethyst/core Version 0.2.* | — | — |
amethyst/file Version 0.2.* | — | — |
railken/template Version 1.0.* | — | — |
amethyst/data-builder Version 0.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.