The MIT license and small dependency set make the package easy to inspect. Use the listed replacement, annotate/events, instead of adopting this release.
12%
Total Score
0
100
38
50
Packagist marks the entire package as abandoned and names annotate/events as its replacement, making this release unsuitable for a new dependency.
The last release was published on February 9, 2015, and there have been no releases in more than 11 years, indicating abandonment.
The repository has recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and lack of ongoing maintenance.
The artifact and repository each contain only composer.json, leaving little source or documentation transparency for consumers of this library.
The package has no README, tests, or changelog, although the repository uses GitHub releases and this exact version has a GitHub release; the lack of consumer documentation remains a modest gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kdyby/events Version ~2.3 | — | — |
annotate/extensions-installer Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.