Its six-file footprint and lack of security tooling leave little evidence of ongoing care. The MIT declaration and matching repository provide useful transparency, but this release should be treated as legacy code.
32%
Total Score
0
75
75
The package has only one release, published in August 2016, with no releases in the last 12 months. Nearly ten years without another release is strong evidence of abandonment risk.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the unchanged release history and indicating no current maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than decisive, but these counts provide no meaningful external sign of adoption or review.
Composer is used for builds, but no security scanning tools are present. This is a maintenance and review gap for a package that has not otherwise shown recent activity.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds a transparency gap to the broader maintenance concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version 1.18.2 | — | — |
guzzlehttp/guzzle Version 6.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.