The MIT license, matching repository, and stable release provide a sound foundation. Documentation is extremely thin and the repository has no tests or security policy. No releases or commits since February 2020 make ongoing maintenance the main concern.
43%
Total Score
0
50
75
The package has 27 releases since April 2017 and a stable latest version, but it has had no release in the last 12 months and its latest release was in February 2020. The long period without a release indicates substantial abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no release activity since February 2020.
The artifact has a README, but it is only 6 characters, and neither the package nor repository has tests or a changelog. For this library, the extremely limited documentation and absent tests reduce transparency and confidence.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no external adoption signal to offset the stale maintenance record.
Composer build tooling is present, but no security scanning tooling is configured. This is a maintenance and assurance gap, though it is less serious than the lack of recent project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | — | — |
mezzio/mezzio-hal Version ^1.3 | — | — |
tightenco/collect Version ^5.7 | — | — |
laminas/laminas-db Version ^2.11 | — | — |
doctrine/collections Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.