The package is clearly licensed, includes a consumer README, and has repository tests with no install-time scripts. Its unpinned workflow actions add minor maintenance exposure, and the linked repository does not identify this package, making provenance less clear.
12%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the release.
Only two releases were published, both in January 2020, with no release in about 6 years. This strongly indicates the package is no longer maintained.
The repository had no commits and no active maintainers in the last 3 months. Combined with its archived status, this confirms absent current development activity.
The linked source repository is archived, so it is no longer an active maintenance home even though it was last pushed about 3 years ago. That makes fixes and ongoing compatibility unlikely.
The linked repository name does not match the package name and its README does not mention the package. That weakens confidence that it is the package's intended source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.