The release is stable, licensed, and documented with release notes. Maintenance has stopped for about 20 months, while workflow references are entirely unpinned and the linked repository does not clearly identify this package.
40%
Total Score
50
79
50
Composer install, update, and project-creation scripts are present. These scripts add install-time behavior that should be understood before adoption, but their presence alone is not evidence of poor maintenance.
The package has 35 releases since November 2021, but none in the last 12 months; its latest release was about 20 months ago. This strongly raises abandonment risk despite the previously active cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
There were no new or closed issues or pull requests in the last month, while six issues and two pull requests remain open. This suggests limited recent project attention.
The repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established. This is a transparency concern even though the file tree resembles the package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cmb2/cmb2 Version ^2.9 | — | — |
timber/timber Version ^2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.