Its README, tests, changelog, and MIT license make the package easy to inspect and adopt. The small dependency footprint and lack of install scripts reduce operational risk, but there is no recent maintenance or security tooling.
38%
Total Score
0
100
67
83
The package has had only one release, on May 5, 2020, with no releases in the last six years. That strongly indicates abandonment risk for a library intended to track changing package versions.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been untouched since May 2020. This is strong evidence that defects and compatibility changes may go unaddressed.
The repository has one star and no forks, providing little evidence of community review or shared maintenance capacity. Popularity is supporting evidence only, so this does not determine the score alone.
Composer build tooling is present, but no security-scanning tool is configured. The missing scanning is a maintainability and assurance gap, though it is secondary to the long inactivity.
The linked repository is not archived, but its last push was on May 7, 2020; the active archive status does not offset the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version 2.* | — | — |
guzzlehttp/guzzle Version 6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.