The package includes a substantial source tree, tests, documentation, and an MIT declaration. Its last release and repository push were in February 2016, with no commits in the latest three months, so current compatibility and support are uncertain.
42%
Total Score
0
80
50
The latest release was on February 27, 2016, and there were no releases in the last 12 months. The package had 62 releases historically, but the long period without a release indicates substantial abandonment risk.
The repository had no commits and no active maintainers in the latest three months, consistent with the release history showing no release activity since February 2016.
The package runs post-install and post-update Composer scripts. These add installation complexity and warrant review, although the signal alone does not show that the scripts are unsafe.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though it is secondary to the much older maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
doctrine/inflector Version ^1.0 | — | — |
doctrine/annotations Version ^1.2 | — | — |
eloquent/enumeration Version ^5.1 | — | — |
ocramius/proxy-manager Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.