The project has clear documentation, an MIT license, and a maintained source repository. Its sole recent contributor, absent security policy, and unpinned workflow references add adoption risk; use the replacement package instead.
38%
Total Score
67
69
50
Packagist marks the package itself as abandoned and points to friends-of-behat/mink-debug-extension as the replacement. This directly makes the assessed package a poor dependency choice.
The latest registry release was nearly six years ago, with no releases in the last 12 months. That is a substantial freshness concern for a dependency, despite the package having ten releases overall.
All three recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization backing helps with handoff potential, but no second active contributor is shown.
The repository had three commits in the last three months, indicating some current maintenance. However, this activity does not correspond to a fresh registry release for the assessed package.
The project uses Composer build tooling, but no security-scanning tools were detected. The missing scanner is a modest transparency and maintenance concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.5 | — | — |
behat/mink-extension Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.