The README, tests, release notes, and lack of install-time scripts make adoption clearer and safer. A single maintainer and no security policy or scanning provide limited support and security visibility.
38%
Total Score
50
72
75
The package has had no releases in the last 12 months, and its latest release was about six years ago despite being a data-integration library. This is strong evidence that maintenance has stopped.
Only one registry account publishes the package, leaving a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of broader maintenance capacity.
The repository has 1 star, 1 fork, and 1 watcher, indicating a very small user and contributor base. Popularity is only supporting evidence, but this provides little independent confidence in long-term support.
Composer build tooling is present, but no security-scanning tools are reported. The build setup is adequate while security visibility remains limited.
The repository is not archived, which is a positive sign, but it was last pushed about six years ago. The absence of archival status does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabpot/goutte Version ^4.0 | — | — |
guzzlehttp/guzzle Version ^6.5|^7.0.1 | — | — |
tightenco/collect Version ^7.2|^8.0.4 | — | — |
intervention/image Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.