Recent repository activity, tests, and release notes show the code is maintained elsewhere; the linked repository does not mention this package. Use gemorroj/ginfo instead.
38%
Total Score
50
70
50
Packagist marks the entire package abandoned and explicitly names gemorroj/ginfo as its replacement. This is a major adoption risk even though the linked repository remains active.
All recent commit activity comes from one contributor, leaving maintenance dependent on a single active person.
The repository had only 1 commit in the last 3 months, indicating limited recent maintenance activity despite a recent push.
The linked repository is named ginfo rather than linfo and does not mention this package in its README, creating uncertainty about whether it is the intended source.
The repository has no security policy, which limits transparency around vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.4||^8.0 | — | — |
symfony/http-client Version ^7.4||^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.