It has tests, a clear README, release notes for this version, and no install-time scripts or deprecation notice. Maintenance has gone quiet for about six months, while the workflow uses three unpinned actions and the repository has no security scanning.
66%
Total Score
50
100
83
75
The source repository is owned by an individual rather than an organization, so the single registry maintainer reflects a thin maintainer base rather than organizational backing.
The package has four releases over about two years and one release in the last year, with a median interval of about nine months. This is a slow cadence but not abandonment by itself.
There were zero commits and zero active maintainers in the last three months. Together with the slow release cadence, this is a meaningful maintenance concern.
The repository has zero stars, two forks, and one watcher. Low visibility is supporting evidence of a small project, but it is not a health verdict because the package can still be maintained by a small team.
Composer is used for the build, but no security scanning tools are configured. This is a transparency and hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
symfony/serializer Version * | — | — |
symfony/property-access Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.