The MIT license, included tests, and Composer build setup provide useful transparency. There is no security policy or scanning, so oversight remains weak.
38%
Total Score
50
64
75
This package has only one release, published about 12 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a library dependency.
One registry maintainer is consistent with a small user-owned project, but there is no organizational backing shown and the project has not released updates for about 12 years.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these figures provide little supporting evidence of an active user or contributor community.
The repository is not archived, which is a positive, but it was last pushed about 12 years ago. The lack of recent source activity leaves the project effectively stale.
The repository has no security policy and no security scanning tools. This weakens vulnerability-reporting and oversight practices, although it does not by itself show a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/xml Version master-dev | — | — |
cakephp/utility Version master-dev | — | — |
guzzlehttp/guzzle Version 4.* | — | — |
guzzlehttp/command Version 0.6.* | — | — |
guzzlehttp/guzzle-services Version 0.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.