Tests, a README, and a changelog provide useful project context, while organization backing helps. The detected MIT license does not match the declared GPL-3.0+ license, and no security policy is published.
61%
Total Score
67
81
75
The package declares GPL-3.0+ and includes license files, but the detected MIT license does not match that declaration; the mismatch should be resolved before adoption.
The package has had no releases in the last 12 months, despite being about 1 year 7 months old; this indicates a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last 3 months, a concrete sign of slowed maintenance despite its recent push timestamp.
There were no new or closed issues or pull requests in the last month, while seven pull requests remain open; this suggests limited recent project movement.
Composer is used for builds, but no security scanning tools were detected; this is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.2 | — | — |
amphibee/hookable Version 1.0.0 | — | — |
symfony/serializer Version ^5.2 | — | — |
composer/installers Version ^2.2 | — | — |
tgeorgel/objectpress Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.