It has a clear README and release notes, and its dependencies are explicit. The one-person project has no recent commits and no security policy, making future fixes and support unlikely.
10%
Total Score
25
100
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning that future maintenance and compatibility support should not be expected.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. That lack of observed activity makes fixes for dependency or tool changes unlikely.
The linked repository is archived, so it is no longer an active development target. Its last push was about 3 months ago, reinforcing the abandonment risk.
No license declaration or license file was detected in the package or repository. That creates a legal transparency gap for consumers.
Only one registry maintainer is listed, and the project is backed by a personal repository rather than an organization. This leaves limited visible capacity for continued maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpro/grumphp Version 2.21.0 | — | — |
carthage-software/mago Version 1.40.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.