The repository has no recent commits or active maintainers, leaving compatibility fixes unlikely. The package is documented and small, but its maintenance signals do not support a dependable new dependency.
12%
Total Score
0
100
42
Packagist marks the entire package as abandoned, with no replacement named. Package-level deprecation is a severe adoption risk even though this is a stable release.
This package has only one release, published nearly four years ago, with no releases in the last 12 months. That provides little evidence of sustained maintenance.
There were no commits and no active maintainers in the last three months, consistent with the archived repository and indicating no current maintenance capacity.
The linked repository is archived and was last pushed nearly four years ago, so ongoing fixes and compatibility work should not be expected.
The repository name does not match the package name and its README does not mention the package, creating uncertainty about whether the linked source is the intended project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.