The linked project is active, but all recent commits come from one contributor and the repository does not clearly identify this package. Its tiny release history and old pre-1.0 version add uncertainty for long-term use.
15%
Total Score
75
50
75
The package is explicitly abandoned at the registry and has a package-wide replacement, friendsofouro/geteventstore; this is a direct reason not to adopt this release.
There has been only one release, published over 10 years ago, with no releases in the last 12 months. The replacement project may be active, but this package itself is not maintained through releases.
One contributor made all 12 recent commits, leaving no demonstrated contributor redundancy. The organization-owned project provides some backing, but the observed maintenance capacity remains concentrated.
The repository name does not match the package name and its README does not mention this package, so the linkage is not clearly established. That creates a transparency concern even though name differences can occur in reorganized projects.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. This is a modest transparency gap, not a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version ~1.4 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
dbellettini/eventstore-client Version ~0.8 | — | — |
kevinrob/guzzle-cache-middleware Version ^0.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.