The MIT file is present, but the manifest names “WobbleCode,” creating a licensing mismatch. There is no published security policy, and the README is brief.
32%
Total Score
0
50
50
The latest release was in November 2017, with no releases in the last 12 months and only three releases overall. This strongly suggests the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus and a substantial abandonment risk.
The artifact contains an MIT license file, so the release is licensed, but the manifest declares “WobbleCode” instead of MIT. That mismatch reduces metadata clarity.
The repository name does not match the package name and its README does not mention the package, so ownership of the published package is less transparent despite the repository being under the same organization.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than decisive, but these values provide no additional adoption or community-maintenance confidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hwi/oauth-bundle Version ^0.5|^0.6 | — | — |
symfony/framework-bundle Version ~3.0|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.