The tiny README and absent security policy leave little guidance for integration or reporting problems. Its simple Composer build is clear, but the package needs careful replacement planning because maintenance evidence is so old.
30%
Total Score
0
100
67
75
This is the package's only release, published almost 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment rather than a short-term slowdown.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap. No provided signal shows compensating maintenance activity.
The package includes a README, but it is only 32 characters long; missing tests and a changelog are normal for published artifacts and are not concerns here. The minimal README still provides very little consumer guidance.
The repository name matches the package, so it does not look like an unrelated project. However, the README does not mention the package, leaving a small provenance and documentation gap.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to compensate for the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 | — | — |
monolog/monolog Version ^1.18 | — | — |
symfony/filesystem Version ^3.0 | — | — |
kaiyulee/thrift-lib-php Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.