It has clear documentation, an MIT license, tests, and release notes. Its narrow dependencies and organization ownership offer little compensation for the lack of ongoing support.
15%
Total Score
50
100
57
67
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe adoption risk despite the otherwise complete release metadata.
The latest release was about 6 years ago, with no releases in the last 12 months. That prolonged release inactivity is a strong abandonment concern.
The repository had no commits and no active maintainers in the last 3 months. This confirms the absence of current maintenance rather than merely a quiet release schedule.
The linked repository is archived, and its last push was about 3 years ago. This strongly indicates the project is no longer maintained.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a secondary transparency gap alongside the stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
eloquent/phony Version ^4 | — | — |
peridot-php/peridot Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.