The tested source tree, clear BSD license, and matching repository support adoption. However, the only release was about six years ago and the repository has had no recent commits, leaving compatibility and maintenance uncertain.
43%
Total Score
50
71
50
This is a single-release package with no release in about six years, which is a substantial maintenance and compatibility concern. The stable 1.0.0 version and repository tests provide some mitigation but do not show ongoing support.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. Its unarchived state and existing test suite reduce, but do not remove, abandonment risk.
The repository has one star, no forks, and one watcher, providing little evidence of a broad user or contributor community. Low popularity is supporting evidence rather than a verdict, but it offers little compensation for the maintenance gap.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest hygiene concern and does not by itself establish that the release is unsafe to depend on.
The repository has no security policy, leaving no documented channel or process for reporting security issues. This is a transparency gap, although it is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rindow/rindow-event Version 1.* | — | — |
rindow/rindow-stdlib Version 1.* | — | — |
rindow/rindow-container Version 1.* | — | — |
interop-phpobjects/lenient-aop Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.