Risky to adopt: this package has had only one release and no repository activity for about 7 years. It has a matching source repository, a usable README, and no deprecation or install scripts, but the long abandonment gap and minimal community activity make it a maintenance liability.
45%
Total Score
50
100
75
50
The package has only one release, published about 7 years ago, with no releases in the last 12 months. This is strong evidence of an immature or abandoned dependency.
The repository recorded no commits and no active maintainers during the last 3 months, consistent with the package's long release gap. No provided signal shows current maintenance to compensate for this.
The repository has zero stars and forks and only 4 watchers, providing little evidence of community use or review. Popularity is supporting evidence rather than decisive on its own, so this is a caution rather than a severe risk.
The repository uses Composer for its build or dependency workflow, but has no security scanning tools. Composer provides basic project structure, while the missing scanning is a modest transparency gap.
The repository has no security policy, reducing transparency about vulnerability reporting. This is a hygiene concern, but the small project and absence of analyzed workflows limit its direct significance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
matthiasmullie/minify Version >=1.3.61 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.