The package has a license, documentation, changelog, and repository tests. Its workflow audit found no untrusted checkouts or script injection, but those positives do not restore a dependable maintenance path.
12%
Total Score
63
100
63
67
Packagist marks the entire package as abandoned and points users to addwiki/addwiki, directly indicating that this package should no longer be adopted.
The linked repository is archived, so ordinary project maintenance and issue handling have stopped even though it received one push within the last three months.
Only one registry account has publishing access. The organization-owned repository provides some backing, but the registry publishing path remains concentrated.
This is the only release, published nearly two years ago, with no releases in the last 12 months; that provides little evidence of continuing maintenance.
All recent commits came from one contributor, giving the project a single-person operational path. Organization ownership offers some handoff potential, but no second active contributor is shown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.3||~7.0 | — | — |
benestar/asparagus Version ~0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.