It has a clear MIT license, a usable README, release notes, repository tests, and a substantial source tree. Install and update hooks, missing security scanning, and unpinned workflow actions add hygiene concerns.
56%
Total Score
50
78
50
The package has 221 releases but none in the last 12 months, and its latest release was about five and a half years ago. This strongly lowers confidence in ongoing maintenance, although the long release history shows prior maturity.
The package runs post-install and post-update Composer scripts. These increase install-time behavior and review burden, but the signal alone does not show that the scripts are unsafe.
The repository is owned by an individual user rather than an organization. This does not prove poor stewardship, but it offers less visible institutional backing for a project with no recent activity.
There were no new or merged pull requests in the last month and no issue activity was recorded. Combined with the old last release, this supports a maintenance concern, while the null open-issue count limits what can be concluded.
The repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no visible community backing for a package with no recent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.0 | — | — |
symfony/cache Version ^3.3 || ^4.3 || ^5.0 | — | — |
monolog/monolog Version ^1.22 || ^2.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.2 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.