The package includes a license, tests, usage documentation, and no install-time scripts. Its small dependency set and clean workflow audit do not offset the lack of a maintained project.
10%
Total Score
0
42
75
Packagist marks the entire package as abandoned, with no replacement package listed. This is a severe dependency-health warning because future fixes and support should not be expected.
Only two releases were published, both in May 2022, with no releases in the last 12 months. This long release gap strongly indicates the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms the current lack of development activity rather than merely a slow release cadence.
The linked repository is archived, and its last push was in August 2023. An archived source project is not actively maintained and creates substantial abandonment risk.
Composer is used for the build, but no security-scanning tools are present. This is a modest transparency and maintenance gap, especially for an archived project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
ratchet/pawl Version ^0.4.1 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
gmostafa/php-graphql-client Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.