Clear documentation, repository tests, a changelog, and an MIT license make the package transparent. Its nearly five-year release and commit pause signals abandonment risk. The workflow audit also found a high-confidence unpinned container image.
42%
Total Score
0
78
50
The package has made no release in nearly five years despite 25 historical releases, leaving this version without evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release pause and increasing abandonment risk.
The repository has zero stars, forks, and watchers, offering no supporting evidence of an active user or contributor community; popularity is supporting evidence rather than a verdict.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency for reporting vulnerabilities, although this is secondary to the much stronger maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^5.3.7 | — | — |
spatie/macroable Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.