The repository still includes tests and a useful README, and the package has no install-time scripts. A single maintainer, no security tooling, and no recent issue activity leave little evidence of ongoing care.
42%
Total Score
38
100
71
75
This package has had only one release, published over 12 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the repository remaining available.
There were no commits and no active maintainers in the last three months; the last recorded push was over 9 years ago. This is strong evidence that maintenance has stopped.
The registry lists one maintainer. Because the project is user-owned rather than organization-backed, this provides limited maintenance capacity and increases continuity risk when combined with stale activity.
The package and repository are owned by the same individual account, with no organization backing shown. This is consistent with the single-maintainer continuity risk.
The repository has four open issues and three open pull requests, but none were created or closed in the last month. Unaddressed work without recent activity is consistent with an inactive project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version >=2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.