Risky to depend on: the package has not released since July 2016 and remains on an early 0.2.0 version. It has a matching repository, tests, documentation, and a clear license, but the long period without updates is a substantial maintenance risk.
38%
Total Score
100
100
61
90
The latest release was about 10 years ago, with no releases in the last 12 months and only four releases overall. This strongly suggests the package is no longer actively maintained.
The repository is not marked archived, but its last push was about 10 years ago. The unarchived status does not offset the evidence of prolonged inactivity.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these counters provide little supporting evidence of adoption or community maintenance.
Composer is used as the build tool, showing basic project tooling, but no security scanning tools are present. For a small older package this is a hygiene gap, not the primary risk.
No repository security policy was found. That limits transparency about vulnerability reporting, although the package's small scope and lack of active workflows reduce the significance compared with its maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kevinem/yext-php Version ^0.3.0 | — | — |
illuminate/support Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.