The small package is clearly documented, licensed, and has no install-time scripts. Its maintenance evidence is stale, leaving compatibility and support uncertain despite organization ownership and a non-deprecated registry status.
38%
Total Score
50
50
81
88
The latest release was published in October 2016, and there have been no releases in the last 12 months. The 23-release history shows prior activity but does not offset nearly ten years without a new release.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with no meaningful maintenance since 2016. This is the strongest evidence that adopting the release carries abandonment risk.
The module declares 13 runtime dependencies, creating a relatively broad compatibility surface for a small package. The dependency list is explicit, but no provided signal demonstrates current compatibility across those dependencies.
Only one registry account has publish access, which is a limited publishing base. The organization-owned repository provides some backing, so this is a minor concern rather than evidence of abandonment by itself.
Composer is used as the build tool, which fits the ecosystem. No security scanning tools were detected, a modest transparency and hygiene gap for a package that has not seen recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ride/app Version ^1.0.0 | — | — |
ride/web Version ^1.0.0 | — | — |
ride/app-orm Version ^1.0.0 | — | — |
ride/lib-orm Version ^1.0.0 | — | — |
ride/web-orm Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.