The package includes a clear MIT license, README, tests, and changelog. However, it has had no release or repository activity for over six years, with open work still present and no security policy or scanning. This leaves you carrying an effectively abandoned integration.
38%
Total Score
50
79
75
The latest release was over six years ago, and there were no releases in the last 12 months. The 14-release history shows earlier activity but does not offset the prolonged current inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating a high abandonment risk.
There were no new or closed issues or pull requests in the last month, while 10 issues and 2 pull requests remain open. This suggests unresolved maintenance needs.
Composer build tooling is present, but no security scanning tools were detected. The established build setup is positive, while the missing scanning coverage leaves a supply-chain hygiene gap.
The repository has no security policy, reducing transparency around vulnerability reporting and project response. This is a meaningful gap for a package that exposes application data through a framework integration.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^2.7|^3.0|^4.0 | — | — |
doctrine/dbal Version ^2.5 | — | — |
voku/anti-xss Version 2.1.* | — | — |
algo-web/podata Version 0.3.*|dev-master | — | — |
illuminate/http Version ^5.1.11|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.