The MIT license, release notes, and matching repository make the package straightforward to inspect. Its maintenance appears to have stopped after March 2021, leaving a small codebase with no recent commits or security tooling.
42%
Total Score
75
100
81
83
The package has only two releases, both published on March 11, 2021, with no release in more than five years. This is strong evidence of abandonment risk, although the stable v1.1.0 release provides some maturity.
There were zero commits and zero active maintainers in the last three months. Combined with the repository's 2021 last push, this indicates sustained inactivity rather than a short pause.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, secondary to the much stronger inactivity evidence.
The linked repository is not archived, but it was last pushed on March 11, 2021. The unarchived status is positive, while the old last-push date supports the maintenance concern.
The repository has no security policy. For a small dependency container this is a transparency gap, though it is less significant than the lack of recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
reliese/component-dependency Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.