The project has no recent commits, issues, or releases, and its single maintainer account does not offset the organization-backed repository. It includes tests, release notes, and a matching repository, but those strengths do not address its inactive status.
12%
Total Score
50
56
50
Packagist marks the entire package as abandoned, with no replacement given. Package-wide deprecation is a severe dependency risk even though the specific release is stable.
The package has had no release in nearly five years and none in the last 12 months. Its eight-release history shows an established project, but not current maintenance.
There were no commits and no active maintainers in the last three months. This confirms the absence of ongoing development rather than merely a slow release cadence.
The linked repository is archived, and its last push was nearly three years ago. An archived source project is a strong sign that maintenance and fixes have stopped.
There were no new or closed issues or pull requests in the last month. Combined with the archived repository, this supports an inactive project rather than evidence of healthy stability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.1 | — | — |
21torr/rad Version ^1.0 | — | — |
symfony/yaml Version ^5.2 | — | — |
21torr/assets Version ^1.0 || ^2.0 | — | — |
21torr/hosting Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.