A single publisher and one-star repository provide little evidence of ongoing support. The MIT declaration, matching repository, and README improve transparency, but do not offset the long inactivity.
42%
Total Score
25
63
50
The package has had only three releases, all concentrated in May 2020, and none in the past six years. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with its last push in May 2020. The prolonged lack of activity materially raises abandonment risk.
Only one registry account has publish access, and the project backing identifies an individual owner rather than an organization. That leaves little visible redundancy for continued maintenance.
Composer build tooling is present, but no security scanning tools are configured. This modestly reduces evidence of ongoing quality controls, although it is less significant than the inactive project history.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verdient/bitmap Version ^0.0.1 | — | — |
verdient/chorus Version 0.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.