It includes tests, a changelog, a license, and a repository that clearly matches the package. No releases have appeared since November 2017, the repository is archived, and registry status marks the package abandoned.
12%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement listed. Package-level deprecation is a severe adoption risk because future fixes and support are unlikely.
The package has 11 releases over about 9 years, but none in the last 12 months and the latest release was about 8 years and 10 months ago. This confirms prolonged inactivity rather than a short release pause.
The repository had zero commits and zero active maintainers in the last 3 months. Together with its archived state, this indicates no active maintenance capacity.
The linked repository is archived, and its last push was about 5 years and 9 months before collection. An archived source project is a strong sign that this release is no longer maintained.
The single workflow was fully analyzed with no reported audit findings or dangerous triggers, but both of its two action references are unpinned. That is a minor reproducibility and supply-chain hygiene weakness, not the reason for the overall verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
opis/closure Version ^2.1.0 | — | — |
rollun-com/rollun-dic Version ^2.2 | — | — |
zendframework/zend-db Version 2.8.2 | — | — |
rollun-com/rollun-utils Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.