It has clear packaging, a matching source repository, and release notes for this version. Maintenance has stopped for about three years, while the license mismatch and unpinned workflow actions add transparency and build risks.
57%
Total Score
67
81
67
A LICENSE file is present in both the artifact and repository, but it is detected as MIT while the manifest declares BSD-3-Clause. The mismatch reduces transparency even though the release is licensed.
The package has 12 releases since 2015, but none in the last 12 months and its latest release was about three years ago. This long pause is a meaningful maintenance concern.
There were no commits or active maintainers in the last three months, consistent with the roughly three-year release gap and indicating a substantial abandonment risk.
There were no new or closed issues or pull requests in the last month, and no work is currently queued. Combined with the inactive commits, this supports the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest repository hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.10 | — | — |
phpunit/phpunit Version 6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 | — | — |
guzzlehttp/guzzle Version ~6 || ~7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.