Its MIT license, included tests, and single runtime dependency make the codebase straightforward to inspect. The repository has no security policy and very little observed adoption.
38%
Total Score
50
100
78
50
The package has 70 releases but none in the last 12 months, and its latest release was over eight years ago. This long period without a release strongly raises abandonment risk.
There were zero commits and zero active maintainers during the last three months. Combined with the repository's last push being over eight years ago, this is strong evidence that maintenance has stopped.
One registry account has publish access. The linked repository is owned by the same individual account, so this is a thin maintainer base rather than organization-backed continuity.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of community support.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap that matters more because the project has also been inactive for years.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webfactorybulgaria/core Version ^4.1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.