Documentation, tests, a changelog, and a clear MIT license are in place. However, the release is about nine years old and the repository has had no commits or active maintainers in the last three months, making abandonment the main concern.
32%
Total Score
33
50
72
75
The package was first released about nine years ago but has had no releases in the last 12 months, indicating that it is no longer actively delivered or maintained.
There were zero commits and zero active maintainers in the last three months, strongly indicating that maintenance has stopped.
Eight runtime dependencies create a meaningful maintenance surface for an old client library, though the profile is not extreme and no dependency-specific failure is shown.
The repository is owned by an individual user rather than an organization, so there is no organizational backing shown to compensate for the thin maintenance evidence.
There were no new or closed issues or pull requests in the last month, and no pull requests were open, providing no evidence of current project interaction.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jane/open-api Version ^1.0 | — | — |
guzzlehttp/psr7 Version ^1.2 | — | — |
symfony/process Version ^2.3 || ^3.0 | — | — |
php-http/message Version ^1.0 | — | — |
symfony/filesystem Version ^2.3 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.