Its MIT license, README, and Composer metadata make the package easy to inspect. The single-person project has had no commits or releases since July 2018, and it has no security scanning or policy.
42%
Total Score
25
75
75
Only two releases were published, both in July 2018, with no release in roughly eight years. This is strong evidence of abandonment risk, although the package is not marked deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
There were no new or closed issues or pull requests in the last month, and two issues remain open. This supports the broader picture of inactive maintenance.
The repository has only 6 stars, 2 forks, and 1 watcher. Low adoption is supporting evidence rather than a verdict, but it provides little community capacity to compensate for inactivity.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning reduces assurance for a package that has otherwise seen no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.0 | — | — |
symfony/cache Version * | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
adbario/php-dot-notation Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.