The project has a clear README, tests, and Composer-based packaging, but no security scanning or security policy. Its small maintainer and contributor base leaves little visible capacity for support.
48%
Total Score
33
50
81
75
The package has had no release in more than 7 years, with 0 releases in the last 12 months. Its eight-release history and stable 1.0.7 version provide some maturity, but the prolonged inactivity is a substantial maintenance concern.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the package's last release being in 2019. This is strong evidence that maintenance has effectively stopped.
The package declares nine runtime dependencies, including several PHP extensions and SOAP-related libraries. This is a meaningful integration surface but not, by itself, evidence of abandonment or unsafe maintenance.
Only one registry maintainer is listed, which limits publishing redundancy. The repository is also owned by an individual rather than an organization, so no organizational backing compensates for that thin base.
The repository owner is an individual account, not an organization, and no broader project backing is shown. That leaves the package dependent on a very small apparent maintenance base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-ds/php-ds Version ^1.2 | — | — |
monolog/monolog Version ^1.24 | — | — |
artisaninweb/laravel-soap Version 0.3.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.