Risky to adopt: the package has had no release in about six years and its repository has not been updated since June 2020. It is not deprecated or archived and includes a README, but the long-term inactivity makes maintenance and compatibility a serious liability.
38%
Total Score
50
67
Only two releases were published, both in June 2020, with no releases in the last 12 months; the latest release is about six years old. This is strong evidence of abandonment risk despite the stable release version.
The package declares 37 runtime dependencies spanning multiple frameworks and services, creating a substantial compatibility and maintenance surface for a release that has not been updated in years.
The manifest declares a Commercial license and provides no license file, while the package README says the project is MIT-licensed. This unresolved licensing conflict creates a real adoption and transparency concern.
The repository is not marked archived, which is a compensating sign, but its last push was in June 2020 and aligns with the package's long release gap. The repository therefore appears inactive rather than actively maintained.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.5 | — | — |
filp/whoops Version ^2.3 | — | — |
ramsey/uuid Version ^3.8 | — | — |
symfony/flex Version ^1.3.1 | — | — |
symfony/intl Version 5.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.