It includes a README, tests, changelog, and a declared license, with no install scripts. The repository has no recent commits, and the registry marks the package abandoned in favor of appserver-io/appserver.
12%
Total Score
0
58
75
Packagist marks the entire package as abandoned and names appserver-io/appserver as its replacement. This is a severe adoption risk because new maintenance is directed elsewhere.
The package has had no releases in over 11 years, despite 25 releases during its earlier active period. That long release gap strongly indicates abandonment for a dependency intended for ongoing use.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push over 11 years ago. This provides no evidence of current maintenance capacity.
The linked repository neither matches the package name exactly nor mentions the package in its README, creating some uncertainty about package-to-repository alignment. The repository name is nevertheless closely related, so this is a secondary concern.
The repository has no security policy. This is a transparency gap, but it is secondary to the package's explicit abandonment and long period without releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version 2.4.* | — | — |
techdivision/naming Version 0.1.* | — | — |
herrera-io/annotations Version 1.0.* | — | — |
mtdowling/cron-expression Version 1.0.* | — | — |
techdivision/servletengine Version 0.8.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.