Example project
30%
Total Score
0
69
75
The latest release was over six years ago, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment for a package intended as a dependency.
The repository had zero commits and zero active maintainers in the last three months, consistent with its last push in November 2019. There is no observed recent maintenance to offset the age of the release.
The artifact has no README, tests, or changelog, while the repository also has no tests or changelog. Missing tests and changelogs are normal packaging practice, but the absent README reduces consumer documentation for this library.
The repository name does not match the package name, and no README package reference was found. A name mismatch can be normal for a subpackage, but here the available evidence does not establish that relationship.
Composer is used as the build tool, which is appropriate for a Packagist package, but no security scanning tooling is present. This is a modest hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.