Usable with caveats: the package is licensed, not deprecated or archived, and its repository matches the package. However, it has had no release or commit activity for nearly four years and provides little documentation or security process, so verify it still meets your needs before adopting it.
54%
Total Score
75
81
75
The package contains no README, tests, or changelog, and the repository has no tests or changelog. Missing tests and changelog are acceptable for published artifacts, but the missing README is a real usability and transparency gap for a library consumers must integrate.
The latest release was published on October 7, 2022, with no releases in the following 12 months; by the collection date, this represents nearly four years without a release. The earlier nine releases show that the project was once active, but current maintenance is a concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, which reduces the severity but does not demonstrate ongoing maintenance.
Composer is used as the build tool, providing basic ecosystem-appropriate package tooling, but no security scanning tools were detected. The lack of scanning is a modest process gap rather than a severe risk because no workflow risk was observed.
No security policy was found. This does not prove a security problem, but it leaves the process for reporting and handling vulnerabilities unclear, especially alongside the absence of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version >=1.0 | — | — |
gipfl/cli Version >=0.5 | — | — |
gipfl/json Version >=0.1 | — | — |
gipfl/systemd Version >=0.3 | — | — |
react/promise Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.