The package includes tests, a README, and a simple dependency profile. Its source has seen no commits or releases for about 12 years, and it has no security scanning or policy, making long-term maintenance a substantial concern.
38%
Total Score
25
100
67
83
The package has only one release, published about 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency that may need ongoing compatibility maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history showing no activity for about 12 years.
One registry account has publish access. This is not a concern by itself, but it provides little visible publishing redundancy when combined with the long absence of releases and commits.
The repository uses Composer and Phing, showing build tooling, but it has no security-scanning tools. That is a transparency and maintenance gap, though not evidence that the package is unsafe by itself.
The repository is not marked archived, which avoids the strongest abandonment indicator, but it was last pushed about 12 years ago and therefore does not compensate for the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.