The package has a clear license, a focused README, and no install-time scripts. Its large dependency set increases upkeep exposure, while the archived project and long release silence make this release unfit for a new dependency.
18%
Total Score
50
50
67
100
The last release was published about seven years ago, with no releases in the past 12 months. Although the package had 45 releases historically, this indicates prolonged abandonment.
The repository had zero commits and zero active maintainers in the past three months, consistent with the archived state and extended release silence.
The linked repository is archived and was last pushed about six years ago. This is a severe maintenance and abandonment risk for a dependency.
The package declares 36 runtime dependencies, creating substantial transitive maintenance and compatibility exposure. That breadth may be expected for a core dependency bundle, but it increases the cost of relying on an inactive release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.1.* | — | — |
embed/embed Version ^3.0.0 | — | — |
punic/punic Version ^3 | — | — |
symfony/yaml Version ^4.2 | — | — |
tedivm/stash Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.