The repository is tiny, has no tests or security scanning, and has only one registry maintainer. Its MIT licensing, clear README, and organization backing provide useful transparency but do not offset the lack of ongoing maintenance.
35%
Total Score
50
78
83
The package has made only two releases, with the latest in July 2017, and has had no releases in the last 12 months. This long period without updates is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since July 2017.
Only one account has registry publishing access. The organization-owned repository provides some backing, so this is a limited resilience concern rather than a severe standalone risk.
There were no new or merged issues or pull requests in the last month. With no recent commits or releases, this supports the conclusion that the project is inactive rather than merely stable.
The repository has zero stars, two forks, and one watcher, offering little evidence of a broad user or maintainer community. Low popularity is supporting evidence only, but it provides no offset to the inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.