The repository matches the package and includes a clear license, README, tests, and release notes. Its maintenance appears abandoned, with no recent commits or releases and unresolved issues, so pinning this version carries meaningful long-term risk.
35%
Total Score
25
75
50
The latest release was on January 20, 2020, and there were no releases in the last 12 months. This long release gap is strong evidence of abandonment risk despite the package having nine releases overall.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package having received no updates since January 2020.
Three issues and one pull request remain open, with no new or closed issues or pull requests in the last month. This supports the concern that maintenance has stopped.
Composer build tooling is present, but no security scanning tools are configured. This is a modest supply-chain hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. That is a transparency and incident-response gap, although it is less significant than the clear maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.