The package is licensed, has a matching repository, and installs without lifecycle scripts. It lacks tests, security scanning, and meaningful adoption signals, leaving compatibility and issue response uncertain.
40%
Total Score
0
67
75
Only two releases were published, both in April 2018, with no releases in the last 12 months. This strongly indicates abandonment risk despite the package not being formally deprecated.
The repository recorded zero commits and zero active maintainers during the measured three-month period, consistent with the stale release history and raising maintenance risk.
The package includes a README, while missing tests and a changelog are normal for published artifacts and are not gaps by themselves. The README is only 19 characters, so consumer guidance is minimal.
The repository has only 1 star, 0 forks, and 1 watcher, providing little evidence of broad community use or backup support if the sole maintainer stops responding.
Composer is used for builds, but no security scanning tooling is present. This is a hygiene gap that adds some transparency risk without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ~3.0|~4.0 | — | — |
symfony/process Version ~3.0|~4.0 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
symfony/filesystem Version ~3.0|~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.