It has a clear MIT license, tests, a useful README, and a matching organization-owned repository. Its small dependency footprint and lack of install scripts reduce exposure, but the project shows little security or maintenance oversight.
38%
Total Score
50
100
67
75
The latest release was nearly 10 years ago, with no releases in the last 12 months. Eight historical releases show the package was once maintained, but the long silence is a strong abandonment concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the nearly 10-year-old latest release and indicating no current maintenance activity.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently harmful, but alongside the absence of commits it provides no evidence of an active support process.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, especially for a project with no recent development activity.
The linked repository is not archived, which is a positive counter-signal, but it was last pushed nearly 10 years ago and therefore does not offset the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version ~2.6|~3.0 | — | — |
aboutcoders/process-control Version ~1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.