The README, changelog, MIT license, and organization-backed repository make the package easy to inspect and integrate. Its small footprint and lack of security tooling provide less assurance than a currently active project.
58%
Total Score
83
83
75
The package has 32 releases over more than 12 years, but none in the last 12 months; its latest release was over two years ago. This is meaningful evidence of stalled maintenance, though the long release history shows prior maturity.
There were no commits and no active maintainers in the last three months, consistent with the release pause and raising a real abandonment-risk concern. The repository is not archived, which limits the severity.
The repository has no stars or forks and only seven watchers, indicating a very small visible user base. Popularity is supporting evidence only, so this modestly limits external validation rather than determining the verdict.
Composer is used for the build, but no security scanning tool is present. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a maintenance and transparency gap, but not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ride/app Version ^1.0.0 | — | — |
ride/lib-log Version ^1.0.0 | — | — |
ride/lib-orm Version ^1.6.0 | — | — |
ride/lib-i18n Version ^1.0.0 | — | — |
ride/lib-system Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.