The README and small dependency set make the package straightforward to inspect and adopt. Its last release was about 11 years ago, and the repository has had no commits in roughly seven years. There are no tests or security scanning tools to support confidence in future maintenance.
35%
Total Score
33
50
72
83
The package has made no release in roughly 11 years, despite five releases earlier in its history. That long gap is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was roughly seven years ago. That sustained lack of development is a substantial abandonment concern.
Six runtime dependencies, including an image library and AWS SDK, create a meaningful maintenance surface for an old PHP package. The dependency count is still modest and does not independently indicate that the package is unsafe to adopt.
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to compensate for the single-maintainer structure or stale activity.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a quiet project, but does not by itself prove abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version 1.* | — | — |
aws/aws-sdk-php Version 2.* | — | — |
imagine/imagine Version * | — | — |
nategood/commando Version * | — | — |
composer/installers Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.