The MIT license, matching license file, and lack of install-time scripts reduce basic adoption friction. Its long-standing lack of maintenance leaves compatibility and future-fix risk unresolved.
35%
Total Score
0
60
75
The package has had no release in about seven years, despite 10 releases arriving within roughly one day in April 2019. This is strong evidence of abandonment rather than an actively maintained release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and leaving no evidence of current maintenance capacity.
Release notes exist for this exact version, documenting a disk-usage formatting fix. The artifact has no README, which is a minor documentation gap for a library consumers must integrate.
Composer is used for the build, but no security-scanning tooling is present. That weakens repository hygiene, though it is less significant than the absence of recent development.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a secondary transparency gap alongside the much larger maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.2 | — | — |
symfony/process Version ^4.2 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.