Its minimal artifact has no tests, changelog, or security scanning, limiting confidence in future fixes. MIT licensing, a matching repository, and no install scripts reduce adoption friction, but do not offset the long-term inactivity.
40%
Total Score
0
71
75
This is the only release, published over six years ago, with no releases in the last 12 months; that is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance.
The repository has only 2 stars and no forks, which is supporting evidence of limited adoption but is not decisive by itself.
Composer is used for builds, but the repository has no security scanning tool; this is a meaningful hygiene gap for a package handling IP data, though not severe alone.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package with no recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ipip/db Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.