The MIT license, focused ten-file tree, and Composer setup provide basic transparency. The small project footprint and lack of security scanning leave little additional assurance for a package this old.
35%
Total Score
50
64
83
The package has had no release in nearly 10 years: its latest release was August 24, 2016, despite three releases overall. This is strong evidence of abandonment for a dependency expected to receive maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push being in August 2016. This indicates severe abandonment risk.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, the absence of any package reference makes repository ownership less transparent.
The repository uses Composer, providing build tooling, but has no detected security scanning tools. That is a modest transparency and maintenance gap, not a standalone adoption blocker.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities. This adds a modest maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ride/web Version >=0.10.0 | — | — |
ride/lib-mvc Version ^1.0.0 | — | — |
ride/lib-form Version >=0.14.0 | — | — |
ride/lib-http Version ^1.0.0 | — | — |
ride/lib-i18n Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.