The MIT license, README, tests, and two runtime dependencies make the 23-file package relatively easy to inspect. Its only release was over eight years ago, and the repository has had no commits or active maintainers in the last three months, so abandonment risk is high.
42%
Total Score
25
100
69
83
This package has only one release, published over eight years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite the absence of a registry deprecation.
There were no commits and no active maintainers in the last three months. Combined with the single old release, this is concrete evidence of a project that is no longer being maintained.
The repository is owned by a user account rather than an organization. That offers no visible organizational backing to compensate for the thin maintenance record.
The repository uses Composer, but no security scanning tools were detected. The missing scanning is a transparency and hygiene gap, although it is less important than the long-term inactivity.
The linked repository is not archived, which leaves open the possibility of future maintenance. Its last push was over eight years ago, so this does not offset the observed inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yurunsoft/yurun-php Version dev-dev | — | — |
yurunsoft/yurun-event Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.