The package is clearly structured, licensed, tested, and backed by a matching organization repository. Its release and commit activity has stalled, while install-time scripting and unpinned workflow actions add avoidable maintenance risk.
60%
Total Score
75
50
88
67
The package has 11 runtime dependencies, including several project-owned components, creating a moderate dependency surface that raises update and compatibility burden.
A post-install-cmd script runs during installation, adding execution and maintenance risk compared with a package that has no install-time scripts.
The package has 20 releases over more than 6 years, but has made no release in the last 12 months; this is a meaningful sign of slowing maintenance.
There were no commits from any active maintainers in the last 3 months, weakening confidence that defects and dependency changes will be addressed promptly.
Composer is used for builds, but no security-scanning tooling is present, leaving a notable repository hygiene gap for dependency health.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
suin/php-rss-writer Version ^1.6 | — | — |
librarianphp/command-web Version ^1.2 | — | — |
librarianphp/command-help Version ^1.1 | — | — |
librarianphp/command-build Version ^1.2 | — | — |
librarianphp/command-cache Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.