The package includes tests, a usable README, and a clear repository match, but it also runs Composer install/update hooks and has no security scanning or policy. Its very small dependency surface does not offset the maintenance and transparency concerns.
12%
Total Score
0
100
50
67
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning that maintainers do not recommend continued dependency use.
This package has only one release, published in August 2017, with no releases in the last 12 months. The lack of release history indicates that the package is no longer maintained.
There were no commits and no active maintainers in the last three months. Together with the old release history, this confirms inactive development rather than a temporary lull.
The linked repository is archived, and its last push was in April 2018. An archived source repository is a severe abandonment risk for a dependency.
The package defines post-install and post-update Composer scripts, so dependency installation can execute package-provided code. This is not a health verdict by itself, but it increases the importance of ongoing maintenance and transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
consolidation/robo Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.