The release includes notes, a README, repository tests, and a clear MIT license. The package is marked abandoned, recent commit activity is absent, and its workflow uses an unpinned container image.
42%
Total Score
50
75
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a substantial adoption and maintenance risk even though other signals show a recent release.
The package has existed for over 10 years with 19 releases and one release in the last 12 months. That recent release is positive, but the relatively sparse cadence limits confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens the evidence for sustained maintenance despite the recent push shown by another signal.
The project uses Composer and Make, but no security-scanning tooling was detected. The missing scanner is a modest transparency and hygiene gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.