The README, test suite, matching license, and organization ownership provide useful adoption and accountability signals. Nearly five years without a release or commit, plus no security policy or scanning, leaves ongoing support uncertain.
58%
Total Score
67
100
79
50
The package has 17 releases but none in nearly five years, with the latest published on October 27, 2021; this is strong evidence of stalled maintenance.
There were no commits and no active maintainers in the past three months, consistent with the nearly five-year release gap and increasing abandonment risk.
Composer is used for builds, but no security scanning tools are configured, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^6.0 | — | — |
monolog/monolog Version >=1.17 | — | — |
guzzlehttp/guzzle Version >=6.3 | — | — |
cazco-digital/data-object Version ^1.1.1 | — | — |
cazco-digital/event-observer Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.