The package has a small runtime dependency and clear source layout, with no install-time scripts. Organization backing, release notes, and a matching repository provide useful context, but this old release offers limited evidence of ongoing support.
40%
Total Score
75
100
75
88
The artifact includes license files, but the declared LGPL-3.0-or-later does not match the detected GPL-3.0 text. That mismatch creates avoidable licensing uncertainty for adopters.
The package has had no release in about five years and no releases in the last 12 months, indicating a substantial abandonment risk despite six historical releases.
There were zero commits and zero active maintainers in the last three months, consistent with the long release hiatus and strengthening the abandonment concern.
Composer is used as the build tool, but no security scanning tools are reported. The missing scanning is a hygiene gap rather than evidence that the release is unsafe to depend on.
The repository is not archived, but its last push was about five years ago, so the non-archived status does not offset the observed maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jenssegers/blade Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.