The package is clearly identified, licensed, and avoids install-time scripts. Its single maintainer and minimal documentation reduce resilience, while the repository has been inactive since late 2020.
42%
Total Score
25
75
83
The package has had no release in nearly six years: its latest release was in November 2020, with zero releases in the last 12 months. Four releases show an established history but do not offset the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating a high abandonment risk.
Only one registry account can publish releases, which limits publishing resilience. The organization-owned repository provides some backing and makes a short registry maintainer list less concerning.
The artifact includes a README, but it is only 14 characters long and provides little consumer guidance. Missing tests and a changelog are normal packaging practice, while the GitHub release provides some release transparency.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.4 | — | — |
laminas/laminas-db Version ^2.11 | — | — |
laminas/laminas-code Version ^3.4 | — | — |
composer/package-versions-deprecated Version 1.11.99.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.