Risky to adopt: this release is explicitly marked abandoned on Packagist and has a replacement package. The source repository is active and well-scaffolded, but recent work comes from one contributor, so migration to the replacement should be preferred.
38%
Total Score
67
75
83
Packagist marks the entire package as abandoned and names aspose-cloud/aspose-words-cloud as its replacement. Although the current release is recent, depending on an abandoned package creates substantial continuity risk.
One contributor made all 7 commits in the last 3 months, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository had 7 commits in the last 3 months, showing ongoing work. However, all recent activity came from one active maintainer, limiting the strength of that compensation.
The repository name does not match the Packagist package name and its README does not mention that exact package name. A name mismatch can be normal for a subpackage, but the absent README reference leaves package-to-repository linkage less transparent.
Composer is used for builds, but no security-scanning tool is reported. The missing scanner is a transparency gap for supply-chain maintenance, though it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.13 | — | — |
phpseclib/phpseclib Version ^3.0.55 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.