It includes a substantial README, tests, and a source repository that clearly matches the package. The declared GPL-2.0+ license conflicts with the detected GPL-3.0 license, and the repository has no security policy or scanning tools. No install-time lifecycle scripts are present.
12%
Total Score
0
43
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because future maintenance and support are not indicated.
The package has 138 releases but none in the last 12 months; its latest release was about 7 years and 8 months ago. The earlier rapid release history does not compensate for the prolonged inactivity.
The repository recorded no commits and no active maintainers during the measured 3-month period. This supports the broader evidence of abandonment.
The linked repository is archived, and its last push was about 7 years and 8 months ago. An archived source project is a strong sign that this release is no longer maintained.
A license file is present, but the manifest declares GPL-2.0+ while the artifact license is detected as GPL-3.0. The mismatch creates avoidable legal uncertainty for adopters.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
matthiasmullie/minify Version ^1.3 | — | — |
mobiledetect/mobiledetectlib Version ^2.8 | — | — |
tijsverkoyen/css-to-inline-styles Version ^2.2 | — | — |
yahnis-elsts/plugin-update-checker Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.