The organization-backed repository matches the package, includes a useful README, and has a clear license. Its tiny release history, absent recent commits, and lack of security scanning make long-term maintenance uncertain.
38%
Total Score
50
100
71
75
This is the package's only release, published in October 2019, with no releases in the following 12 months or since. That strongly raises abandonment risk, despite the stable version designation.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in October 2019. There is no provided evidence of ongoing maintenance.
The repository has zero stars and one fork, providing little supporting evidence of adoption or external review. Popularity is only supporting evidence, so this modestly lowers confidence rather than determining the verdict.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate for the package, while the missing scanning reduces maintenance assurance.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities. This is a meaningful transparency gap for a dependency, though it does not by itself show a security problem.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
techdivision/card-shuffle Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.