The MIT license and repository tests provide a useful baseline, and the package has no install-time scripts. Its narrow maintainer base and absent security scanning leave little evidence of ongoing stewardship.
34%
Total Score
50
50
72
83
The package was released only three times, all within about 6 days in November 2016, and has had no release in more than 9 years.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing that maintenance has collapsed for years.
Four runtime dependencies, including the Symfony framework and Docker client libraries, create meaningful transitive maintenance exposure for an otherwise small package.
Two registry maintainer entries exist, but both names identify the same apparent individual; this is a thin publishing base, though repository ownership is organizational.
There are no open issues or pull requests and no activity in the last month; this is consistent with a dormant project rather than evidence of healthy resolution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version ~3.0@stable | — | — |
myclabs/deep-copy Version 1.*@stable | — | — |
docker-php/docker-php Version 1.*@stable | — | — |
cscfa_tool_division/collections Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.