Healthy and reasonable to adopt. It has frequent releases, an active unarchived organization-backed repository, matching package sources, and repository tests, though recent work is concentrated in one contributor and no security policy is present.
82%
Total Score
88
100
88
88
All 8 commits in the last 3 months came from one contributor, creating a genuine continuity risk; organization backing provides some mitigation because maintenance can potentially be handed off.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and preventive-maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
Version 0.44.0 is not a stable major release, so compatibility guarantees may be weaker, but it is not a prerelease and recent releases are consistent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flow-php/snappy Version self.version | — | — |
packaged/thrift Version ^0.15.0 | — | — |
flow-php/filesystem Version self.version | — | — |
symfony/polyfill-mbstring Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.