The package has a clear license, repository tests, a changelog, and a matching source repository. Its missing security policy and absent security scanning reduce transparency, while the available maintenance evidence is too old to support a current dependency.
39%
Total Score
50
67
83
The package has had no release in over 10 years, and all 23 releases are concentrated at its initial publication. This is strong evidence of abandonment for a library consumers may still depend on.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its last push being over 10 years ago. No provided maintenance signal compensates for this inactivity.
There were no new issues, closed issues, or pull requests in the last month, and no pull requests were open. This supports the broader picture of an inactive project, though issue data is partly incomplete.
The project uses Composer and Make, showing basic build structure, but it has no detected security scanning tools. The missing scanning is a modest hygiene concern rather than evidence of unsafe code.
The repository is not marked archived, which avoids an explicit abandonment status, but its last push was over 10 years ago and the lack of activity outweighs that administrative status.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.