Risky to adopt: this package is marked abandoned on Packagist, with a replacement package named. The linked repository is active and well-scaffolded, but recent commit activity is currently absent, so prefer the replacement and verify its maintenance before depending on it.
40%
Total Score
75
79
50
Packagist marks the entire package as abandoned and points to swag-industries/melodiia as its replacement. That is a direct adoption risk, despite the package having a recent release.
The package defines a post-install command, which adds install-time behavior that should be reviewed before adoption. No other provided signal establishes that the script is harmful, so this is a limited caution rather than a severe risk.
The repository recorded no commits and no active maintainers in the last three months. Although a recent release exists, the current lack of development activity raises maintenance risk.
The repository uses Make and Composer for builds, but no security scanning tools were detected. The build setup is a positive sign, while the missing security scanning leaves a modest transparency gap.
No repository security policy was found. This weakens vulnerability-reporting transparency, though it does not by itself indicate abandonment or make the package unusable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^7.5.1 | — | — |
symfony/yaml Version ^7.0 || ^8.0 | — | — |
nekland/tools Version ^2.5.1 | — | — |
symfony/serializer Version ^7.0 || ^8.0 | — | — |
league/uri-components Version ^7.5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.