Usable with caveats: the project is clearly backed, tested, licensed, and maintained with good repository hygiene, but it has had no release for about 21 months and no commits in the last 3 months. Depend on it only if its current, stable feature set is sufficient.
68%
Total Score
75
100
94
80
The package defines post-install and post-update Composer scripts, which require some trust during installation; this is common for application templates but adds operational exposure compared with a package without install-time scripts.
The package has five releases since November 2020, but none in the last 12 months and the latest release was about 21 months ago. This is a meaningful maintenance concern, though not evidence of abandonment by itself.
There were zero commits and zero active maintainers in the last 3 months, indicating currently paused development and increasing the risk that issues or compatibility needs may not be addressed promptly.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a small stable project, but it does not provide evidence of active ongoing maintenance.
Neither workflow declares top-level token permissions. No workflow requests write access, but explicit least-privilege permissions would provide stronger CI configuration hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.3|^3.3 | — | — |
httpsoft/http-basis Version ^1.1 | — | — |
devanych/di-container Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.