Clear licensing, documentation, tests, and release notes support adoption basics. The package is abandoned in practice, with no releases or commits for roughly nine years, and its registry status marks it deprecated.
18%
Total Score
50
64
83
Packagist marks the entire package as abandoned, with no replacement listed. This is a direct warning against taking a new dependency on the package.
The last release was published roughly nine years ago, and there were no releases in the last 12 months. The 20-release history shows past activity but does not offset the prolonged absence of updates.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with long-term abandonment rather than active maintenance.
The repository uses Composer build tooling, but it has no security-scanning tools. This is a minor hygiene gap, not the main reason the release is unfit.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the prolonged lack of maintenance is the more consequential concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1 | — | — |
psr/http-message Version ~1 | — | — |
doctrine/annotations Version ^1 | — | — |
doctrine/instantiator Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.