The package includes a license, README, tests, changelog, and no install-time scripts. Its source has no recent maintenance or security policy, leaving little evidence that it can support a current project.
8%
Total Score
50
50
88
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry explicitly signals that the package should no longer be used.
This release was published about 12 years ago, and it is the package's only release; there have been no releases in the last 12 months. The absence of a release history indicates abandonment rather than a stable active cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months. Together with the archived state, this confirms there is no current development activity.
The linked repository is archived, and its last push was about 8 years ago. Archival strongly indicates that ongoing maintenance and issue response are unavailable.
The repository has no security policy. That is a transparency and response gap, although the license, tests, and documentation provide some compensating project structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http-client Version 0.4.* | — | — |
litgroup/dns-bundle Version 0.1.* | — | — |
symfony/framework-bundle Version ~2.3 | — | — |
litgroup/event-loop-bundle Version 0.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.