Risky to adopt: the package has had no release or repository activity for about four years, and its small single-owner project has little evidence of ongoing support. It is not deprecated or archived, and it includes tests, but maintenance risk is substantial.
42%
Total Score
33
50
72
83
The package has made no releases in the last 12 months, with all 17 releases concentrated around its initial June 2022 launch. This is strong evidence of prolonged inactivity.
There were zero commits and zero active maintainers in the last three months, consistent with roughly four years without repository updates. This is a direct abandonment risk for a dependency.
The package declares eight runtime dependencies, including Codeception and several PHP extensions, which increases integration and maintenance surface for a small library. The dependency list is visible, but its breadth raises compatibility risk.
Only one registry account has publishing access. That is not conclusive by itself, but combined with the observed inactivity it provides little evidence of resilient ongoing support.
The artifact includes a README and tests, and the repository also has tests and uses GitHub releases. The README is only 19 characters and there is no changelog, leaving limited consumer guidance, though the missing changelog is not inherently a packaging problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.4 | — | — |
symfony/serializer Version ^2.8.52 | — | — |
codeception/codeception Version ^4.1 | — | — |
symfony/property-access Version ^2.8.52 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.