It has a clear MIT license and extensive documentation, but 44 runtime dependencies increase upkeep. Missing security guidance and all 10 workflow actions are unpinned, adding maintenance and build-reproducibility concerns.
12%
Total Score
50
50
57
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption and maintenance warning even though the release itself is not separately withdrawn.
The package has 50 releases, but none in the last 12 months; its latest release was about 2 years and 2 months ago. Earlier frequent releases do not compensate for the prolonged current inactivity.
The repository recorded no commits and no active maintainers during the last 3 months. This reinforces the abandonment signal rather than showing an isolated release pause.
The linked repository is archived, and it was last pushed about 1 year and 9 months ago. An archived source project is a strong indication that ongoing fixes and support should not be expected.
The package declares 44 runtime dependencies, spanning framework, database, messaging, AI, and web components. That broad dependency surface raises upkeep and compatibility exposure, especially for an inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
rubix/ml Version ^2.5 | — | — |
grpc/grpc Version ^1.57 | — | — |
twig/twig Version ^3.7 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.