The package is clearly licensed, documented, and its repository matches the package. Nearly ten years without a release or commit makes abandonment a serious concern; choose a maintained alternative if available.
38%
Total Score
25
100
72
75
The latest release was in November 2016, with no releases in the last 12 months. Nearly ten years without a new release is strong evidence of stagnation.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating a serious abandonment risk.
The package and repository are owned by the same individual account, so the source ownership is consistent, but there is no organizational backing shown.
The repository has only 1 star and 1 fork, offering little community evidence or backup capacity. Popularity is supporting evidence, so this reinforces rather than determines the concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
raven/raven Version 0.15.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.