The package includes a clear README, tests, release notes, and a source repository that matches the package. It lacks a security policy, while its workflow uses three unpinned actions and has a low-confidence cache warning.
58%
Total Score
33
100
81
83
There were no commits and no active maintainers in the last three months, consistent with nearly five years since the last push and indicating substantial abandonment risk.
The package and repository are owned by the same individual account, so there is no observed organizational backing to compensate for the thin maintenance base.
The latest release was nearly five years ago, with no releases in the last 12 months. Its five-release history shows an established package, but not current maintenance.
There are no new or closed issues in the last month and one open pull request, providing no evidence of active project response.
The repository uses Make and Composer, but has no detected security-scanning tools. This is a hygiene gap, not evidence that the package is unmaintainable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wikimedia/composer-merge-plugin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.