It has an MIT license, tests, organization-backed source, and no install-time scripts. The very short documentation and absent security policy leave limited transparency for maintenance decisions.
40%
Total Score
75
79
75
The latest release was in July 2019, with no releases in the past 12 months and only four releases overall. This is strong evidence of abandonment risk despite a historically regular median interval of about 71 days.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing no activity for roughly seven years.
The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these figures provide little external evidence of ongoing community use.
Composer is used for builds, but no security scanning tooling was detected. This is a transparency and hygiene gap, not evidence of malicious behavior.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This adds a modest transparency concern alongside the long inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ~3.3|~4.0 | — | — |
carno-php/config Version ~2.0 | — | — |
carno-php/promise Version ^1.0 | — | — |
carno-php/log-slim Version ^1.0 | — | — |
symfony/var-dumper Version ~3.3|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.