Healthy and reasonable to depend on, with strong project history, clear licensing, tests, and a current stable release. Recent repository activity is quiet and the project lacks security tooling, so review maintenance periodically.
78%
Total Score
67
89
75
There were no commits and no active maintainers in the last three months, which is a maintenance concern for a dependency. However, the package has a release in the last year and the repository was recently pushed, so this is caution rather than abandonment evidence.
The repository has six open issues but no issues or pull requests were opened, closed, or merged in the last month. That indicates limited visible issue-tracking activity and modestly reduces confidence in responsiveness.
The repository has no stars and only one fork, indicating a small user and contributor footprint. Popularity is supporting evidence rather than a verdict, and the long release history and organization backing compensate for the limited adoption signals.
Composer build tooling is present, but no security-scanning tool is configured. This is a transparency and process gap, though it is not by itself evidence that the package is unsafe or abandoned.
The repository has no published security policy. That makes vulnerability-reporting expectations less clear, but it is a moderate hygiene gap rather than a severe dependency risk given the package's release history and tests.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0.1 || ^2.0 || ^3.0 | — | — |
symfony/yaml Version ^6.0.0 | ^7.0.0 | ^8.0.0 | — | — |
pimple/pimple Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.