The package has a clear README, stable versioning, and no install-time scripts, but its broad dependency set increases upkeep demands and the repository has little community activity. The declared MIT license and matching source repository improve transparency.
42%
Total Score
50
71
75
The latest release was in November 2021, with no releases in the following nearly five years. That is strong evidence of abandonment risk for a package intended as a maintained project skeleton.
The package declares 17 runtime dependencies, including several framework, database, queue, and extension requirements. This creates a substantial compatibility and maintenance burden for an otherwise small skeleton.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of broad community review or support. Low popularity is supporting evidence rather than a decisive failure for a small skeleton.
The repository is not archived, which leaves a path for maintenance, but its last push was in April 2022 and does not offset the long release gap.
The linked repository has no security policy. This reduces transparency around vulnerability reporting, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^4.4 | — | — |
predis/predis Version ^1.1 | — | — |
monolog/monolog Version ^1.26 | — | — |
guzzlehttp/guzzle Version ^6.5 | — | — |
hellogerard/jobby Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.