Risky to adopt for new projects: the last release was about 8 years ago and the repository was last updated shortly afterward. It has a clear MIT license, tests, documentation, and a matching source repository, but the long-standing lack of releases makes maintenance uncertain.
48%
Total Score
50
100
69
88
The package has had no release in the last 12 months, and its latest release was about 8 years ago despite a stable 1.0.2 version. This is strong evidence of abandonment risk, although the package is not registry-deprecated.
The package is backed by the matching individual repository owner, so there is no ownership mismatch. The individual backing is consistent with a small project but offers limited demonstrated maintenance capacity.
Composer is used as the build tool, which is appropriate for a Packagist package. No security scanning tools are present, a modest transparency gap for a package handling message encryption and payment-related callbacks.
The linked repository is not archived, which preserves the possibility of maintenance. However, it was last pushed about 8 years ago, reinforcing the release-history concern.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less severe than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^1.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.