Documentation, tests, and a clear MIT license support basic transparency. Its small dependency set and lack of install scripts reduce operational complexity, but they do not offset the maintenance risk.
12%
Total Score
0
100
63
83
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the release.
The package has had no releases in more than 13 years; its latest release was in August 2013 despite being assessed as a stable major version. This strongly indicates abandonment.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and offering no evidence of ongoing maintenance.
The repository has only 9 stars, 4 forks, and 1 watcher, providing little supporting evidence of broad community adoption. Popularity is secondary and does not independently determine health.
Composer and Phing are used for project tooling, but no security-scanning tool is present. The build structure is positive while the missing scanning coverage is a minor hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
desarrolla2/rss-client Version ~2 | — | — |
symfony/framework-bundle Version ~2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.