The package has a clear Apache 2.0 declaration, tests, documentation, and release notes. Its install-time script and lack of security scanning add smaller concerns, but the project is no longer maintained.
12%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement identified. This is a direct warning against taking a new dependency on it.
The latest release was about 11 years ago, with no releases in the last 12 months. The short historical release interval does not compensate for the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last 3 months. This confirms the project has no current maintenance activity.
The linked repository is archived and was last pushed about 8 years ago. Archived source indicates the project is no longer maintained.
A post-install command runs during installation, adding execution-time supply-chain surface. No additional evidence shows that this script is unsafe, so this is a limited concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/lumen Version 5.1.* | — | — |
league/flysystem Version ^1.0 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
lesstif/php-jira-rest-client Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.