Risky to adopt: the latest release was published nearly six years ago and the repository has had no commits or active maintainers in the last three months. It is licensed, clearly backed by the matching repository, and has a usable README, but maintenance appears effectively abandoned.
38%
Total Score
25
100
75
83
The package has had no releases in the last 12 months, with the latest release nearly six years ago. The six-release history shows an established package but does not offset the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, providing strong evidence that maintenance has stopped.
Only one registry account can publish releases, leaving a thin maintainer base and limited apparent continuity for a package that has already been inactive for years.
Composer build tooling is present, but no security scanning tooling was detected. That leaves less evidence of ongoing automated maintenance.
The repository is not marked archived, which is a positive sign, but its last push was nearly six years ago; the non-archived status does not compensate for the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jeremeamia/superclosure Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.