The single-maintainer, tiny repository offers little evidence of ongoing support. MIT licensing and a matching repository help with transparency, but they do not offset the long maintenance gap.
35%
Total Score
25
71
50
The latest release was about 10 years ago, with only two releases overall and none in the past 12 months. This is strong evidence of abandonment risk for a dependency.
The repository had no commits and no active maintainers in the past three months, consistent with the release history showing no activity for years. The repository is not archived, but that does not demonstrate maintenance.
There has been no issue or pull-request activity in the past month, and one issue remains open. This adds modest evidence that the project is not actively supported.
The repository has zero stars, one fork, and one watcher. Popularity is only supporting evidence, but these very low figures provide little community support to offset the maintenance gap.
Composer build tooling is present, but no security-scanning tooling was detected. This is a secondary transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~5.3|~6.0 | — | — |
illuminate/container Version >=5.0 | — | — |
swiftmailer/swiftmailer Version ~5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.