Risky to adopt: this package has had no release or repository activity since January 2019, and the linked repository does not identify the package in its name or README. It may still work, but maintenance and package ownership are difficult to verify.
35%
Total Score
0
63
75
There has been only one release, published in January 2019, with no releases in the last 12 months. This is strong evidence of an unmaintained package rather than a mature, stable release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the only release and indicating no visible ongoing maintenance.
The package includes a README and has a GitHub release for this version, but the README is only 13 characters and the repository has no tests or changelog. The release record provides some documentation of publication, but consumer guidance and maintenance evidence are minimal.
The repository name does not match the package name and its README does not mention the package, so the repository may not clearly belong to this package. The organization backing reduces some ownership concern, but does not resolve the identity gap.
The repository uses Composer, which is appropriate for a PHP package, but it has no security scanning tools. This is a process gap that adds some transparency risk, though it is less significant than the lack of maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
symfony/polyfill-apcu Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.