It has clear licensing, documentation, tests, and a matching source repository. The repository is not archived, but no commits were recorded in the last three months and no security policy is present.
34%
Total Score
50
75
50
Packagist marks the entire package as abandoned, rather than withdrawing only this release. That is a strong warning about future maintenance and makes this release risky to adopt.
The package has 70 releases over nearly 10 years, but none in the last 12 months; its latest registry release was in January 2022. This long release gap indicates that the published dependency is no longer actively maintained.
No commits or active maintainers were recorded in the last three months. The repository is not archived, but the absence of recent development does not offset the abandoned registry status.
There were no new or closed issues and no pull requests in the last month, with 23 issues still open. This supports the picture of stalled project activity.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a meaningful transparency gap for a self-hosted CI server.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
maknz/slack Version ^1.7 | — | — |
symfony/yaml Version ^4.4 | — | — |
pimple/pimple Version ^3.3 | — | — |
symfony/cache Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.