The README, repository tests, and release notes make the small package understandable. Its license declaration covers the detected GPL-3.0 license, but workflow permissions and unpinned actions add maintenance risk.
15%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe warning against taking a new dependency on it.
Only two releases were published, both in January–February 2020, with no release in roughly six years. This supports a conclusion of prolonged abandonment.
The linked repository is archived, which strongly indicates the project is no longer accepting normal maintenance despite a push recorded in August 2025.
The repository recorded no commits and no active maintainers in the last three months. This provides no evidence of current maintenance capacity.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, although it is secondary to the abandonment indicators.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.