The package includes a clear README, broad tests, and matching MIT licensing, with no install-time scripts or deprecation. Its single release was published nearly ten years ago, and repository activity shows no sign of ongoing maintenance, making long-term compatibility a serious concern.
40%
Total Score
50
50
75
83
This is the package's only release, published nearly ten years ago, with no releases in the last 12 months; that strongly indicates abandonment risk.
The package declares nine runtime dependencies, including Symfony and Prooph components; this is a meaningful integration surface for an old single-release package and may increase compatibility maintenance burden.
Only one registry account has publishing access. That is not inherently unhealthy, but combined with the single-release history it provides limited visible publishing resilience.
The repository is owned by an individual account rather than an organization, so there is no organizational backing to compensate for the thin maintenance history.
The repository has no new issues or pull requests in the last month, which is consistent with the absence of recent releases and provides no evidence of active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
prooph/common Version ^3.7 | — | — |
symfony/config Version ^3.1 | — | — |
prooph/event-store Version ^6.5 | — | — |
symfony/http-kernel Version ^3.1 | — | — |
symfony/http-foundation Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.