The repository is still connected to an owning organization and includes tests, licensing, and a package-specific README. Its nearly three-year commit gap and absent security policy add maintenance and transparency concerns.
18%
Total Score
75
64
50
Packagist marks the entire package as abandoned, with no replacement named. That is a direct warning against taking a dependency on this release.
The latest release was nearly 12 years ago, and there have been no releases in the last 12 months. The 38-release history shows prior activity but does not offset this prolonged abandonment.
The repository recorded no commits and no active maintainers in the last three months. This reinforces that the package is not being actively maintained.
Composer build tooling is present, but no repository security-scanning tooling was detected. This is a modest transparency and maintenance weakness, not a standalone adoption blocker.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, adding a minor transparency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kisma/kisma Version ~0.2 | — | — |
dreamfactory/oasys Version @stable | — | — |
dreamfactory/package-installer Version dev-develop as dev-master | — | — |
dreamfactory/lib-php-common-platform Version dev-develop as dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.