The package has useful documentation, tests, a clear MIT license, and a repository that matches its published name. Its small audience and missing security tooling add little reassurance for a dependency that has seen no recent maintenance.
44%
Total Score
50
100
72
83
The package has had no releases in the last 12 months, and its latest release was published roughly 11 years ago. This is strong evidence of abandonment risk, although the project has a completed release history rather than an unproven initial release.
There were no commits and no active maintainers in the last three months. Given that the release is roughly 11 years old, this is strong evidence that development has stopped.
Nine issues remain open, with no new or closed issues and no pull-request activity in the last month. Combined with the old last release, this indicates unresolved maintenance needs.
The repository has zero stars, one fork, and three watchers. Popularity is only supporting evidence, but these low figures provide little evidence of a broad community able to sustain the project.
The repository uses Make and Composer, showing basic build structure, but it has no detected security scanning tools. The missing security tooling is a modest transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
symfony/yaml Version ~2.5 | — | — |
symfony/console Version ~2.6 | — | — |
container-interop/container-interop Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.