The repository has tests and the release is MIT-licensed, but its single-person ownership and absent security policy reduce confidence. Pin this version only when continued Hack/HHVM compatibility is not a concern.
42%
Total Score
0
71
75
The package has only three releases and none in the last six years; the latest release was published in February 2020. This is strong evidence of abandonment risk despite a previously established release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no observed ongoing maintenance.
The linked repository name does not match the package name and its README does not mention the package, so the repository may not clearly document or represent this package.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no meaningful community-maintenance signal.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a hygiene gap that compounds the lack of recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hhvm/hsl Version ^4.25 | — | — |
hhvm/hhvm-autoload Version ^3.0 | — | — |
hhvm/hsl-experimental Version ^4.25 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.