The package is clearly identified, MIT-licensed, and easy to inspect. Its five-file tree and lack of tests or security policy leave little evidence of ongoing engineering beyond the basic wrapper. Pinning this old integration requires accepting maintenance risk.
40%
Total Score
0
100
71
67
The package has had only 3 releases, all concentrated between November 25 and December 1, 2016, with no release in nearly 10 years. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, and its last push was in December 2016. No provided signal shows compensating recent maintenance.
The artifact and repository each contain only 5 files, including one provider class and basic metadata. That is plausible for a narrow wrapper, but it leaves little visible project structure to demonstrate maturity.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene gap, not a standalone adoption blocker.
The repository is not archived, which avoids a hard abandonment marker, but its last push was still in December 2016. The active status does not offset the long inactivity shown by release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zephia/olx Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.