A clear GPL license, README, and no install-time scripts are positives. Its 54 runtime dependencies increase upgrade exposure, while no release or issue activity has appeared since May 2020. Pinning it leaves you with an unmaintained dependency set.
38%
Total Score
50
50
71
50
The package has 25 releases but none in the last 12 months, and its latest release was published in May 2020. That long period without a release is strong evidence of abandonment risk.
This metapackage declares 54 runtime dependencies, creating substantial upgrade and compatibility exposure for consumers. The broad dependency set is consistent with its compilation role but still increases maintenance burden.
There were no new issues or pull requests in the last month and no merged pull requests. Combined with the old last release, this indicates no observable recent project activity.
The repository has zero stars, forks, and watchers, providing no supporting evidence of an active user or contributor community. Low popularity alone is not decisive, but it offers no compensation for the stale maintenance signals.
Composer is used as the build tool, which fits this package, but no security scanning tools are present. This is a modest transparency and hygiene gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.1.3 | — | — |
psr/cache Version 1.0.1 | — | — |
symfony/lock Version v3.4.39 | — | — |
symfony/yaml Version v3.4.39 | — | — |
doctrine/dbal Version v2.9.3|2.10.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.