The MIT license, release notes, and modest dependency set make the package easy to evaluate. Its long maintenance gap and unclear repository ownership make future fixes and support harder to trust.
45%
Total Score
50
100
50
75
The latest release was in January 2022, with no releases in the following four years. That is strong evidence of abandonment risk for a library users may need to keep compatible with current PHP dependencies.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has not seen active maintenance. Combined with no releases for years, this materially raises abandonment risk.
The linked repository name does not match the package name, and its README does not mention the package. That makes it unclear whether the repository is actually the package's source, despite the matching owner namespace.
The repository has zero stars and one fork, so there is little visible community adoption or outside support. Popularity is supporting evidence rather than a verdict, but it provides no meaningful buffer here.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version 2.50.0 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
symfony/translation Version v4.4.26 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.