The only release was published about 9 years ago, and the repository has had no commits or active maintainers in the last 3 months. The MIT license, substantial README, and matching repository improve transparency, but do not offset the clear abandonment risk.
38%
Total Score
38
50
81
83
The package has only one release, published about 9 years ago, with no releases in the last 12 months. This strongly indicates the project is no longer maintained.
There were zero commits and zero active maintainers in the last 3 months. Combined with the one-release history, this is strong evidence of abandonment risk.
The application declares 10 runtime dependencies and 2 development dependencies. This is a sizeable dependency surface for a small, one-release project, though the signal does not show a specific unsafe dependency.
Only one registry account has publish access. The linked project is user-owned rather than organization-owned, so there is little visible publishing redundancy.
The registry namespace and repository are owned by the same individual account, which supports ownership consistency but does not show organizational backing or a broader maintenance team.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
robmorgan/phinx Version ^0.6.3 | — | — |
symfony/routing Version 3.1.* | — | — |
vlucas/phpdotenv Version ^2.3 | — | — |
respect/validation Version ^1.1 | — | — |
illuminate/database Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.