The repository has no tests or security scanning, and its README is only 20 characters. The MIT declaration, matching repository, and lack of install scripts provide some transparency, but they do not offset the absence of maintenance.
38%
Total Score
0
64
75
This is a single-release package first and last published in May 2016, with no releases in the last 12 months. That long publication gap is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and indicating no current maintenance capacity.
The package includes a README, but it is only 20 characters and there are no tests or changelog; the lack of tests and changelog is normal for published artifacts, while the minimal consumer documentation is a real gap for an API client.
The repository has one star, zero forks, and two watchers. Popularity is only supporting evidence, but these very low adoption indicators provide no meaningful community backstop for an inactive project.
Composer is used for the build, which is appropriate, but the repository has no security scanning tools. This reduces ongoing transparency and protection against dependency or build issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version ~1.5.1 | — | — |
symfony/validator Version ~2.7.6 | — | — |
doctrine/annotations Version ~1.2.7 | — | — |
netresearch/jsonmapper Version ~0.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.