The package has clear documentation, tests, a changelog, and organizational ownership. Its security policy and absence of install-time scripts add useful transparency, but the release itself is old and recent repository activity is absent.
58%
Total Score
67
50
81
100
The package declares 35 runtime dependencies, including several framework and infrastructure components; this increases update and compatibility surface, though the signal does not show an inherently unsafe dependency.
The package has 14 releases over about four years, but none in the last two years, leaving this release materially stale despite its previously regular release interval.
The repository had zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have stalled even though the repository is not archived.
There are no open issues or pull requests and no activity in the last month; together with the absent recent commits, this gives little evidence of active maintenance.
The repository uses Make and Composer for builds, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
psr/cache Version ^1.0 | — | — |
ramsey/uuid Version ^3.5 || ^4 | — | — |
opis/closure Version ^3.6 | — | — |
symfony/lock Version ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.