Clear licensing, tests, release notes, and a repository that matches the package make this release transparent to inspect. The registry marks the package abandoned, with no release in 12 months and no commits in the last 3 months, so maintenance risk is significant.
40%
Total Score
50
75
75
Packagist marks the entire package as abandoned, rather than withdrawing only this release. That is a direct warning against taking a new dependency on it, even though the listed replacement has the same name.
The repository had 0 commits and 0 active maintainers in the last 3 months. This indicates little recent maintenance capacity despite the repository not being archived.
The package has 19 releases over roughly 10 years, but none in the last 12 months. Its historical cadence shows maturity, while the current pause raises maintenance concerns.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is secondary to the package's abandonment and inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
concrete5/core Version ^9.2 | — | — |
symfony/dotenv Version ^5|^6|^7 | — | — |
composer/installers Version ^2.2 | — | — |
concretecms/dependency-patches Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.