The small four-file package has no tests, changelog, or README, limiting transparency for a Composer plugin. Its MIT declaration and organization-owned repository provide some context, but no current activity is visible.
40%
Total Score
63
100
56
67
The package has had only three releases, all concentrated on June 19, 2017, with no releases in the last 12 months. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with the release history showing no activity for years and materially increasing abandonment risk.
The package contains only four files, including two source files and composer.json. This may be sufficient for a small plugin, but it leaves little visible project documentation or validation structure.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README limits guidance for consumers of this Composer plugin.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with an inactive project, though it does not independently prove abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.24 | — | — |
symfony/finder Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.