The small user base and lack of security policy or scanning reduce confidence in long-term support. A clear MIT license, release notes, repository tests, and no install-time scripts provide useful safeguards.
58%
Total Score
50
78
75
The package has 25 releases, but its latest registry release was on March 7, 2024, with no releases in the following 12 months. This is a meaningful maintenance concern for a library integration.
There were no commits and no active maintainers during the last 3 months, indicating that current maintenance capacity is very limited.
The repository has only 8 stars, 1 fork, and 3 watchers. Low popularity is supporting evidence of limited adoption, not a severe concern by itself.
The project uses Composer, but no security scanning tools were detected. That leaves a transparency and vulnerability-detection gap, though it is not evidence of malicious behavior.
The linked repository is not archived, but it was last pushed on April 1, 2024, consistent with the observed maintenance slowdown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version >=7.4 | — | — |
doctrine/inflector Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.