It includes a substantial README, tests, and a stable 1.3.2 release. However, the last release and repository push were in 2019, with no recent commits or security policy, so maintenance risk is high.
38%
Total Score
0
64
75
The package has made no release in over 7 years, despite 75 historical releases. This long period without a new release is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months, consistent with the release gap and indicating that maintenance capacity has effectively stopped.
The artifact includes a license file and the repository also has one, so the release is licensed. However, the manifest declares MIT while the detected license is GPL-3.0, creating a meaningful compatibility and transparency concern.
The project uses Composer, but no security scanning tools were found. This is a hygiene gap, though it is less significant than the long-term absence of maintenance.
The repository is not archived, but its last push was in June 2019, so the non-archived status does not compensate for the observed inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alphayax/rest Version ^1.1.2 | — | — |
monolog/monolog Version ^1.9.1 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.