Usable with caveats: the release is licensed, documented, tested, and backed by a matching non-archived repository, but only two releases exist and the latest registry release was over five years ago. The repository has not been pushed since September 2024 and provides no security policy or scanning tooling.
62%
Total Score
50
83
83
The registry namespace and repository are owned by the same individual account, providing direct ownership alignment, though there is no organizational backing to broaden maintenance capacity.
Only two releases have been published since July 2019, with no release in the last 12 months and the latest registry release in December 2020. This is a meaningful maintenance and compatibility concern for a library dependency.
There were no new issues, closed issues, pull requests, or merged pull requests in the last month. With no recent release activity, this leaves current maintenance responsiveness uncertain.
The repository has only 1 star, 3 forks, and no watchers. Popularity is supporting evidence rather than a verdict, but these low levels provide little external evidence of project maturity.
The project uses Make and Composer, showing basic build structure, but no security scanning tools were detected. That is a transparency gap for supply-chain maintenance, though not evidence of unsafe behavior by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.0 | — | — |
nikic/php-parser Version ^4.0 | — | — |
phpdocumentor/reflection Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.