It has a clear MIT license, a matching repository, and no install-time scripts. The short release history, absent recent commits, and missing security policy leave little evidence of ongoing care.
10%
Total Score
25
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct indication that relying on this release is unfit.
Only two releases were published, both in 2021, with no release in nearly five years. That strongly indicates abandonment rather than an actively maintained package.
The repository had zero commits and zero active maintainers in the last three months, reinforcing the lack of current maintenance capacity.
The linked repository is archived, despite being pushed on May 6, 2024, so it is no longer an actively maintained source of fixes or updates.
The repository is owned by the ensi-platform organization, which provides some project backing context. That administrative backing does not compensate for the archived state and absent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
promphp/prometheus_client_php Version ^2.3 | — | — |
promphp/prometheus_push_gateway_php Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.