Risky to adopt: the package has had no release or repository activity for over six years and is maintained by one person. It is clearly packaged, licensed, and tested, but the long abandonment gap makes future compatibility and support uncertain.
45%
Total Score
50
75
88
The latest release was published over six years ago, with no releases in the last 12 months. Six releases arrived during the initial development period, but the prolonged silence is a substantial maintenance concern.
The repository has recorded zero commits and zero active maintainers during the last three months, consistent with the package's long release gap. No newer activity is provided to offset the abandonment risk.
Only one registry publishing account is listed, leaving the project dependent on a single maintainer. The linked repository is user-owned rather than organization-backed, so there is little evidence of maintainer redundancy.
The repository has one star, no forks, and one watcher, indicating a very small user and contributor base. Low popularity is supporting evidence rather than decisive on its own, but it provides little confidence that problems will be noticed or fixed.
Composer is used for the build, which fits the PHP package, but no security scanning tools are present. The missing scanning is a hygiene gap, though it is less significant than the absence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0 | — | — |
brick/varexporter Version ^0.3.2 | — | — |
symfony/filesystem Version ^5.0 | — | — |
gameplayjdk/php-static-help Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.