It includes a README, tests, changelog, MIT license, and no install-time scripts. Its tiny project footprint and lack of security policy provide little evidence of ongoing support for a modern dependency.
35%
Total Score
50
69
50
Only two releases exist, and the latest was published in November 2014; there have been no releases in nearly 12 years. This is strong evidence of abandonment risk.
There are no open issues or pull requests and no issue or pull-request activity in the last month. Combined with the old last push, this supports a conclusion of inactive maintenance.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating very limited visible adoption. Popularity is supporting evidence rather than a verdict, but it reinforces the small project footprint.
Composer build tooling is present, but no security-scanning tooling is reported. The missing scanning is a transparency gap, though it is less significant than the long maintenance hiatus.
The repository has no security policy, leaving no documented path for reporting vulnerabilities. For a server library, this is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.0.0 | — | — |
psr/cache Version 1.0.0 | — | — |
devedge/stubs Version 1.0.* | — | — |
devedge/xmlrpc-common Version 0.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.