Tests and a declared license provide some useful context, and the dependency set is small. However, this one-release package has had no commits or releases since December 2018, while its README explicitly says it is unmaintained; the missing security policy adds further concern.
28%
Total Score
25
100
69
75
The package includes a README and tests, which provide useful consumer and maintenance context, but the README explicitly states that the repository is unmaintained and should be used at the consumer's risk.
The package has only one release, published in December 2018, with no releases in the following years. This is strong evidence of abandonment for a dependency expected to receive maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long period since its last release and indicating no current maintenance capacity.
The repository is owned by a user account rather than an organization, providing no demonstrated organizational maintenance backing. This is consistent with the package's limited maintenance evidence but is not a verdict by itself.
Composer is used as a build tool, supporting reproducible package structure, but no security scanning tools were detected in the repository.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version <102.0.0 | — | — |
php-amqplib/php-amqplib Version ~2.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.