This release has strong evidence of active development and reasonable package hygiene: it is a stable major release, was published recently, has a maintained and unarchived organizational repository, includes tests and a license, and has no install-time scripts. However, Packagist marks the package as abandoned, which is a severe adoption risk even though the repository shows recent activity; the replacement is listed as the same package, so the deprecation reason is unclear rather than reassuring. The very concentrated commit activity and absence of security scanning and a security policy add secondary concerns. Treat this release as unsuitable for a new dependency unless the abandonment status is clarified and the package is confirmed to remain supported.
24%
Total Score
75
100
78
90
Packagist marks the package as abandoned (`is_deprecated: true`), which is a severe dependency-maintenance risk. The listed replacement is the same package, so the ambiguity does not compensate for the explicit deprecation status.
One contributor made about 89.7% of the 29 recent commits, while two others contributed only 2 and 1 commits. The organization ownership provides some handoff capacity, but the observed activity remains highly concentrated.
There are no open issues or pull requests and no issue or pull-request activity in the last month. With recent commits this is not evidence of abandonment, but it provides little independent evidence of community support.
The repository has modest popularity with 8 stars, 3 forks, and 1 watcher. This is limited supporting evidence but is not by itself a health failure for a specialized package.
Composer is used as a build tool, but no security scanning tools are configured. The build setup is appropriate, while the missing scanning is a modest transparency and security-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
neos/neos Version 7 - 8 || dev-master | — | — |
league/csv Version ^9.1 | — | — |
spatie/crawler Version ^8.0 | — | — |
neos/swiftmailer Version ^7.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.