Usable with caveats: this is a stable, licensed package from an organization-backed repository, but the registry release is nearly four years old and recent repository activity shows no active maintainers. Adopt it only if its migration functionality still fits your needs and you can accept limited ongoing maintenance.
58%
Total Score
67
100
88
90
The package has 28 releases since October 2019, but it has had no registry release in nearly four years; that is a meaningful freshness and maintenance concern despite its earlier regular cadence.
The repository recorded zero commits and zero active maintainers over the last three months, a direct sign of currently inactive maintenance and the main adoption concern.
There are only two open issues and six open pull requests, but no new or closed issues or merged pull requests in the last month, indicating little current project throughput.
Composer build tooling is present, but no security scanning tools were detected; this is a transparency and maintenance gap, not evidence that the package is unsafe.
Neither workflow declares top-level token permissions, so the repository has weaker-than-ideal least-privilege workflow configuration even though no top-level write permissions were observed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^1.4 || ^2.0 || ^3.0 | — | — |
symfony/console Version ^3.4.17 || ^4.0 || ^5.0 || ^6.0 | — | — |
laminas/laminas-zendframework-bridge Version ^1.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.