The repository is not archived, the package has a matching source repository, and its license and documentation are clear. However, maintenance has stopped for over three years, with no releases in the last 12 months and 13 unmerged pull requests; workflow references are also unpinned.
58%
Total Score
75
79
67
The package has 131 releases, but none in the last 12 months and the latest release was over three years ago. This is a meaningful maintenance and abandonment concern despite the historically active cadence.
There are 13 open pull requests but no new or merged pull requests in the last month, suggesting unresolved maintenance backlog rather than active development.
Composer is used for builds, but no security scanning tools are configured. This is a hygiene gap, not evidence that the release is unsafe by itself.
The linked repository is not archived, which is positive, but its last push was in March 2023 and other signals show no recent release activity. The unarchived status does not offset the age of the activity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in an API-focused package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/route Version ^5.0.1 | — | — |
league/fractal Version ^0.18 | — | — |
rosell-dk/webp-convert Version ^2.3 | — | — |
0.0.0/composer-include-files Version ^1.6 | — | — |
labor-digital/typo3-better-api Version 10.0.0-beta.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.