Security guidance is absent, and the CI workflow leaves all three actions unpinned. The repository is not archived and the package is clearly identified by its source, but ongoing maintenance is limited.
42%
Total Score
25
100
71
75
The last release was in July 2015, with no releases in the past 12 months despite the package being over 11 years old. This is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the past three months, consistent with the package's prolonged release inactivity.
There are two open issues but no new or closed issues and no pull-request activity in the past month, providing no evidence of an active support process.
The project uses Composer and Make, showing basic build structure, but it has no security-scanning tools. That is a meaningful transparency and maintenance gap for a dependency.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers transparency, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gettext/gettext Version 3.4.* | — | — |
ulrichsg/getopt-php Version 2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.