MIT licensing, organization backing, repository tests, and release notes improve transparency. The lack of a security policy leaves a modest documentation gap.
62%
Total Score
75
88
50
The package has seven releases since March 2019, but none in the last 12 months and the latest was in January 2025. The long median interval of about 292 days indicates slow maintenance, though it is not abandonment by itself.
The repository recorded no commits and no active maintainers in the last three months. This weakens confidence in ongoing maintenance despite the recent release history.
The linked repository has no published security policy. This is a transparency and response-process gap, but it is modest rather than a standalone dependency blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.6|^4.0 | — | — |
event-engine/php-schema Version ^0.3.0 | — | — |
event-engine/php-engine-utils Version ^0.2.1 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.