The package includes a usable README, release notes, a matching MIT license, and repository tests. Its maintenance has effectively stopped, and the registry marks the package abandoned, making this release a poor dependency choice.
15%
Total Score
0
67
50
Packagist marks the entire package as abandoned and provides a replacement link, directly indicating that maintainers no longer recommend depending on it.
The latest release was published in August 2015, with no releases in the following 11 years; this is strong evidence of abandonment for a maintained dependency.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the long period since the last release and offering no evidence of ongoing maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a secondary transparency gap alongside the much stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafo/lessphp Version 0.5.0 | — | — |
leafo/scssphp Version 0.1.9 | — | — |
richthegeek/phpsass Version 2014-03-20 | — | — |
coffeescript/coffeescript Version 1.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.