The package is small and clearly documented, with simple Composer dependencies and organization backing. Its age and lack of recent maintenance make long-term compatibility a significant concern; pinning 0.2.3 is safer than tracking development branches.
32%
Total Score
50
100
71
50
The package has had no releases in nearly 11 years and none in the last 12 months, which is strong evidence of abandonment despite its four historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long maintenance gap rather than showing ongoing upkeep.
Composer is used for the build, but no security scanning tools are reported. This is a minor transparency gap and does not outweigh the historical inactivity.
No repository security policy is present. For a small, inactive package this reduces disclosure transparency, though it is secondary to the much longer maintenance gap.
Version 0.2.3 is not a stable major release, which adds compatibility uncertainty, although it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version 2.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.