It includes a clear MIT license, tests, a changelog, release notes, and no install-time scripts. Security documentation and automated scanning are absent, limiting evidence of ongoing security maintenance.
58%
Total Score
50
50
78
83
The package declares six runtime dependencies, including PHP extensions and established framework or utility components. This is a moderate dependency surface rather than an extreme one, though it adds maintenance exposure for an unmaintained release.
The registry namespace and repository owner match, and the repository is owned by a user account rather than an organization. The matching ownership supports package authenticity, while the individual backing offers limited evidence of maintenance capacity.
The package has 21 releases since February 2016, but none in the last 12 months and the latest was published in November 2020. This long release gap is a meaningful maintenance concern despite the package's established history.
The repository reports zero stars and forks and one watcher. Popularity is only supporting evidence, but these very low engagement levels provide little external evidence of active community support.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a security-maintenance gap, especially alongside the long period without updates.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^2.7|^3.0|^4.0|^5.0 | — | — |
jeremeamia/superclosure Version ^2.2 | — | — |
swiftmailer/swiftmailer Version ^5.4|^6.0 | — | — |
mtdowling/cron-expression Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.