The documented autoload-generation hooks add install-time execution to a very small package. Its MIT licensing, focused file set, and clear README improve transparency, but do not offset the maintenance concerns.
18%
Total Score
0
100
64
50
Packagist marks the entire package as abandoned and names xrstf/composer-php52 as the replacement, making this release unsuitable for a new dependency.
The package has only one release, published nearly 12 years ago, with no releases in the last 12 months; there is no evidence of ongoing release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was nearly 12 years ago, indicating severe abandonment risk.
The package runs post-install, post-update, and post-autoload-dump hooks; these are central to its documented Composer integration, but they add install-time execution risk in an abandoned package.
The repository is not marked archived, which is a small positive, but its last push was nearly 12 years ago and does not show active maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.