Clear licensing, tests, documentation, and a matching source repository provide useful transparency. Its small dependency surface does not offset the absence of current support.
12%
Total Score
25
100
42
Packagist marks the package as abandoned at package scope, with no replacement provided. This is a direct warning against adopting the release.
The last release was in October 2018, with no releases in the following 12 months of the assessment period. A history of 24 releases shows it was once active, but does not compensate for years without releases.
The repository had zero commits and zero active maintainers in the last 3 months. This confirms the lack of current maintenance rather than merely a slow release cadence.
The linked repository is archived and was last pushed in April 2021, indicating the project is no longer maintained.
The artifact includes a license file and the repository also has one, so licensing is transparent. The detected GPL-2.0 text differs from the manifest's GPL-2.0+ declaration, which creates a compatibility detail to resolve.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cocur/slugify Version ^3.1 | — | — |
typo3/cms-core Version ^8.7 || ^9.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.