The repository has had no commits for over 10 years, and there is no recent release activity. It does include a README, tests, Composer build metadata, and an MIT declaration, but those positives do not offset the abandonment risk.
15%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk even though the release itself is not separately withdrawn.
This package has only one release, published over 13 years ago, with no releases in the last 12 months. That strongly indicates abandonment for a dependency intended for ongoing use.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The lack of current development materially raises maintenance and compatibility risk.
The repository has zero stars, one fork, and one watcher, providing little evidence of an active user or contributor community. Popularity is supporting evidence, but these very low figures reinforce the maintenance concern.
The repository uses Composer, showing basic build tooling, but no security-scanning tools were detected. This is a modest transparency and maintenance concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.