The repository is not archived, has a substantial README, and uses Dependabot. The five-year release gap and no recent commits leave no credible maintenance path for a new dependency.
18%
Total Score
50
71
75
Packagist marks the entire package as abandoned, with no replacement supplied. Package-level abandonment is a severe adoption risk even though the repository itself is not archived.
The latest release was over five years ago, with no releases in the last 12 months. Its earlier regular cadence does not compensate for the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms that the package is not receiving current maintenance.
No security policy is present in the repository. That is a transparency gap, though it is secondary for this package compared with the abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^2.6.0 | — | — |
phploc/phploc Version ^4.0 | — | — |
phpro/grumphp Version >=0.11.0,<1.0.0,!=0.11.4 | — | — |
seld/jsonlint Version ^1.6 | — | — |
pdepend/pdepend Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.