The MIT license, matching source repository, and lack of install scripts make the package straightforward to inspect and integrate. Its tiny project footprint and absent security tooling leave little evidence of ongoing support. Pin it only if you can maintain compatibility yourself.
43%
Total Score
50
100
81
75
The latest release was published about seven years ago, with no releases in the last 12 months. This is strong evidence that maintenance has stopped, despite the package having a stable 1.0.9 release history.
There were zero commits and zero active maintainers in the last three months, consistent with the release history and indicating a substantial abandonment risk.
The repository has only 2 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence of a small project, but it is not decisive on its own.
The repository uses Composer, but no security scanning tools were detected. The missing security tooling is a maintenance-hygiene gap, though it is less significant than the lack of recent development.
No repository security policy was found. This weakens vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/period Version ^3.4 | — | — |
zendframework/zend-hydrator Version ^2.3 | ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.