It has a clear README, tests, MIT licensing, and a matching Evaneos repository. The main concern is that releases and commits stopped nearly four years ago, while the repository has no security scanning or security policy.
55%
Total Score
75
100
78
75
The latest release was published nearly four years ago, with no releases in the previous 12 months. This indicates substantially slowed maintenance for a package intended as a reusable library.
There were no commits and no active maintainers during the last three months. Combined with the old last release, this is strong evidence of inactive maintenance.
The repository has only 2 stars and 2 forks, indicating limited adoption and external validation. Popularity is supporting evidence rather than a decisive health judgment, so this is a minor concern.
Composer build tooling is present, but no security scanning tools were detected. That leaves a maintenance and oversight gap, though it is not severe on its own.
The linked repository is not archived, so the project remains administratively available. However, its last push was nearly four years ago, consistent with the maintenance concern shown by release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
evaneos/burrow Version ^4.0 | — | — |
symfony/http-kernel Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.