Risky to adopt: the package has received no release or repository activity for nearly 10 years. It is small and clearly documented with tests, but its maintenance appears effectively abandoned and the linked repository does not match the package name.
42%
Total Score
0
100
64
100
The latest release was published in July 2016, with no releases in the last 12 months, indicating nearly 10 years without a new package release. This is a substantial abandonment risk despite the package having eight historical releases.
The repository recorded zero commits and zero active maintainers in the last three months; together with the last push in 2016, this shows no current maintenance activity.
The repository README mentions the package, which provides evidence that the repository is related, but its name does not match the package name. That mismatch creates some uncertainty about package ownership or repository backing.
The repository has only 3 stars, 3 forks, and 1 watcher. Low popularity is supporting evidence rather than decisive on its own, but it provides little community assurance for a package with no recent maintenance.
The repository is not formally archived, which preserves some possibility of future maintenance, but its last push was in July 2016 and does not offset the long inactivity shown by the release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version * | — | — |
yalesov/arg-validator Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.