Risky to adopt: this package has had only one release, with no repository commits in about 22 months. It is not deprecated or archived and the repository matches the package, but the tiny documentation and absent security tooling leave limited evidence of ongoing maintenance.
45%
Total Score
50
64
75
The package has only one release, published about 22 months ago, with no releases in the last 12 months. This is strong evidence of limited maintenance history for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with a project that may no longer be actively maintained.
A README is present, but it is only 98 characters and provides very limited usage guidance for a library. The absence of tests and a changelog in the package is expected packaging practice and is not penalized.
Composer is used as the build tool, but no security scanning tools are configured. For this small package that is a transparency gap rather than proof of a security problem.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is a secondary concern compared with the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xjryanse/traits Version 0.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.