The package has a usable README and a simple Composer-based build, but it has no license and no recorded maintenance since October 2014. Its single maintainer, absent security policy, and minimal repository activity make long-term support unlikely.
32%
Total Score
50
72
75
This package has had only one release, published nearly 12 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
There were no commits or active maintainers in the last three months, and the repository's last push was in 2014. This is the strongest evidence that the package is no longer maintained.
No declared license, license file, or repository license file was detected. This creates a material legal and transparency concern for dependency adoption.
The package defines post-install and post-update Composer scripts, which warrant awareness because they execute during dependency operations, but the signal alone does not establish a maintenance or adoption failure.
There are no open issues or pull requests and no recent issue or pull-request activity. Combined with the old release history, this supports a lack of ongoing project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bolt/bolt Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.