The release includes a clear README, tests, matching BSD-3-Clause licensing, and a repository that still identifies the package. Its long period without releases or commits, along with unresolved issues and no security policy, makes future maintenance unlikely.
35%
Total Score
50
100
83
75
The repository recorded zero commits and zero active maintainers in the past three months, while its last push was more than 10 years ago. This is strong evidence of abandonment risk.
The last release was published more than 10 years ago, and there were no releases in the past 12 months. Six releases over the package's lifetime show an established history, but not current maintenance.
There are 10 open issues and no issues or pull requests were opened or closed in the past month. This suggests unresolved maintenance demand with no visible recent response.
The repository has 11 stars and 10 forks, indicating limited adoption. Popularity is only supporting evidence, but it offers little additional confidence alongside the lack of recent activity.
Composer is used as a build tool, but no security-scanning tooling is present. The missing scanner is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
unionofrad/lithium Version 1.0.* | — | — |
composer/installers Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.