The package includes tests, a substantial README, release notes, and a matching MIT license. Its seven-year release and commit gap makes maintenance and compatibility uncertain; install scripts add a smaller operational concern.
35%
Total Score
0
50
71
50
The latest release was published in April 2019, and there have been no releases in roughly seven years. This is strong evidence of abandonment for a package intended as a development dependency.
The repository has had zero commits and zero active maintainers in the last three months, with the last push in May 2019. The long-running lack of activity materially increases maintenance and compatibility risk.
The package declares 22 runtime dependencies, including several development-oriented libraries and PHP extensions. This broad dependency surface increases compatibility and maintenance burden for a small, inactive project.
The package runs post-install and post-update Composer scripts, creating additional execution during dependency operations. No provided signal shows these scripts are unsafe, so this is a smaller operational caution rather than a severe risk.
The artifact has a substantial README, tests, and release notes for version 1.0.2, and the repository also contains tests. However, the README explicitly describes the project as alpha and says not to use it yet, which limits maturity confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ~3.0 | — | — |
savvot/random Version ^0.3.0 | — | — |
symfony/finder Version ^4.2 | — | — |
symfony/console Version ^4.2 | — | — |
erusev/parsedown Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.