The artifact is small and clearly matches its repository, with no install scripts or deprecation notice. The unresolved MIT-versus-GPL licensing mismatch and absent security policy add adoption friction.
38%
Total Score
25
64
83
The latest release was published in May 2016, and there have been no releases in roughly 10 years. This is strong evidence of abandonment for a dependency, despite 25 historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the lack of releases for about 10 years. This materially increases abandonment risk.
The manifest declares MIT, but the artifact license file is detected as GPL-3.0. Although a license file exists, the mismatch creates material uncertainty about the terms under which the package may be used.
The package and repository are owned by the same individual account, supporting identity continuity but not organizational maintenance capacity. Combined with one registry maintainer and long inactivity, backing appears thin.
Composer is used as a build tool, which fits the package ecosystem, but no security-scanning tooling is present. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version 4.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.