The package includes a clear README, matching source repository, release notes, and organizational ownership. Its declared GPL-2.0 license conflicts with the artifact's detected GPL-3.0 license, and the repository has no security policy or security scanning.
38%
Total Score
100
70
50
Only two releases were published, both in September 2019, with none in the last seven years. This is strong evidence of abandonment risk for a package intended as a development dependency.
A license file is present, but the manifest declares GPL-2.0 while the artifact license file was detected as GPL-3.0. The licensing terms should be clarified before adoption.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is secondary to the long absence of releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tracy/tracy Version ^2.6 | — | — |
symfony/yaml Version ^4.2 | — | — |
typo3fluid/fluid Version ^2.6 | — | — |
composer/composer Version ^1.9.0 | — | — |
helhum/dotenv-connector Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.