It has an MIT license, a usable README, and release notes for this version. The small dependency set limits complexity, but security coverage is thin.
35%
Total Score
0
100
72
50
Only three releases exist, all from 2016, with no release in the last 12 months. The latest release is about 10 years old, which is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with roughly 10 years since the last repository push. This is the strongest evidence that maintenance has stopped.
The repository has only 2 stars, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of broad community support.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a hygiene concern, especially for a dependency with no recent maintenance.
The repository is not marked archived, but its last push was about 10 years ago, so the non-archived status provides little evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafo/scssphp Version ^v0.6.5 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.