It has a long history, a substantial test suite, release notes, and a matching repository. Composer tooling is present, but no security policy is published and workflow actions are unpinned.
64%
Total Score
25
88
50
There were no commits and no active maintainers in the last three months, with the repository last pushed in December 2024. This is the strongest evidence that active maintenance has currently slowed or stopped.
The package declares a pre-update-cmd lifecycle script. This adds some installation and update complexity, but the signal does not show that the script performs a harmful or opaque operation.
The package and repository are owned by the same individual account, so the source identity is consistent. Individual ownership provides less organizational continuity than a backed project, but it is not evidence of abandonment by itself.
The package has existed since November 2014 with 47 releases, but it had no releases in the last 12 months after version 2.0.0 in December 2024. This supports maturity while raising a current-maintenance concern.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lucatume/args Version ^1.0.1 | — | — |
phpunit/phpunit Version 7.5 - 9.6 | — | — |
antecedent/patchwork Version ^2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.