The package is MIT-licensed, documented with a README, and has no install-time scripts. Its broad runtime dependency set and lack of security scanning provide little reassurance for a library this old.
15%
Total Score
0
50
69
75
The package has 23 releases but none in the last 12 months, and its latest release dates from about nine years ago. This indicates prolonged abandonment risk.
There were zero commits and zero active maintainers in the last three months, confirming that development has stopped rather than merely slowed.
The linked GitHub repository is archived and was last pushed about eight years ago. An archived source project is a severe abandonment signal for a dependency.
The release declares 13 runtime dependencies, creating a relatively broad maintenance surface for an unmaintained library. The signal does not show that any dependency is itself unsafe.
Composer build tooling is present, but no security scanning tools are configured. That is a modest transparency and maintenance gap, especially for an old library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ratchet/pawl Version 0.2.* | — | — |
nesbot/carbon Version ^1.18 | — | — |
react/partial Version ^2.0 | — | — |
react/datagram Version 1.1.* | — | — |
monolog/monolog Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.