The published artifact is minimal, with one runtime dependency and no install-time scripts. Maintenance appears abandoned in practice, and the unverified custom license plus absent tests and security policy add adoption risk.
40%
Total Score
75
100
50
75
The package has had only two releases, both in 2016, with no release in roughly 10 years. This is strong evidence of abandonment for a library dependency.
The manifest declares “SCRINUS,” but no recognized license was detected and no license file exists in either the artifact or repository. This leaves redistribution and usage terms unclear.
One issue remains open, while there has been no issue or pull request activity in the last month. This is consistent with a very small or inactive project and adds to the abandonment risk.
The repository has zero stars and zero forks, with only two watchers. Popularity is supporting evidence rather than a verdict, but these values provide no meaningful evidence of community adoption or review.
Composer is used for builds, which is appropriate for this package. No security-scanning tooling is present, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.