The package has a clear MIT license, tests, and a source repository that matches its name. A single maintainer, no security scanning, and negligible repository adoption provide little resilience for an old dependency.
39%
Total Score
25
75
50
The latest release was published on January 2, 2018, and there were no releases in the following 12 months of observed history; the package has been inactive for about 8 years.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no current maintenance capacity.
Only one registry account has publish access, leaving the release process dependent on a very small administrative base; repository activity does not provide compensating evidence of a broader maintainer team.
The repository has 0 stars, 0 forks, and 1 watcher, offering little community evidence or backup when maintenance is needed.
Composer is used for builds, but no security scanning tools were detected. This is a hygiene gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webfactorybulgaria/core Version ^4.1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.