The MIT license and repository tests make the project understandable to inspect. However, its maintenance and publishing signals show a dependency that should be replaced rather than newly adopted.
12%
Total Score
25
100
64
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The latest release was published in January 2019, and there have been no releases in over seven years. That strongly indicates abandonment for a package intended as a maintained library.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and abandoned status.
The source repository is owned by an organization, which provides some ownership context, but it does not compensate for the package being marked abandoned and inactive.
Composer is used for the build, but no security scanning tooling is present. This is a minor transparency gap, outweighed by the much stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tracy/tracy Version ~2.2 | — | — |
nette/application Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.