Its single-file wrapper has no tests, changelog, or security policy, and the repository has almost no adoption. The MIT declaration and organization-backed repository improve transparency but do not offset the maintenance risk.
15%
Total Score
50
50
57
67
Packagist marks the package abandoned at package scope and names kdyby/events as its replacement. This is a direct warning against taking a new dependency on this release.
The package has only 3 releases, with the latest published over 11 years ago and no releases in the last 12 months. That strongly indicates abandonment rather than active maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and leaving no evidence of ongoing maintenance.
The package is a small wrapper with two runtime dependencies, including kdyby/events, the replacement named by the registry. That supports migrating to the replacement rather than adding another layer.
Both the package and repository contain only composer.json, so there is very little published or maintained source visible. A tiny wrapper can be intentionally minimal, but this still provides weak transparency for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kdyby/events Version ~2.3 | — | — |
annotate/extensions-installer Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.