The package has a clear MIT license, a usable README, and a changelog, but its tiny project footprint offers little evidence of ongoing care. No security scanning or policy is present, so long-term maintenance and transparency remain weak.
42%
Total Score
75
100
63
75
The latest release was published in October 2018, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk for a package intended as a dependency.
The repository has no open issues or pull requests and recorded no recent issue or pull-request activity. This is consistent with a dormant project, although a small package can legitimately have little issue traffic.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful community or adoption signal to compensate for the inactivity.
Composer build tooling is present, but no security-scanning tools were detected. That weakens release transparency for a package with no other recent maintenance evidence.
The repository is not archived, which keeps the source available, but its last push was in November 2018 and therefore does not show current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
mlocati/ip-lib Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.