Documentation, tests, and release notes make integration straightforward. The small dependency surface and organization ownership help, but the long maintenance pause and unpinned workflow actions increase maintenance and build-trust risk.
58%
Total Score
50
100
71
75
The package has had no release in more than three years, despite eight releases overall and a prior median interval of about 98 days. That prolonged pause is a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This raises abandonment risk even though the package may be stable.
The project uses Composer but reports no security-scanning tooling. The missing scanner is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The linked repository is not archived, which is a positive counter-signal to the absence of recent commits. Its last push was still in May 2023, so the repository remains stale rather than actively maintained.
The repository has no security policy. For a small integration bundle this is a limited process gap, but it provides no documented channel for handling future vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
opentracing/opentracing Version ^1.0.1 | — | — |
php-http/httplug-bundle Version ^1.20 | — | — |
auxmoney/opentracing-bundle-core Version ^v1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.