Tests, documentation, licensing, and a small dependency footprint are reassuring. However, the package offers no current maintenance capacity, so choose an actively maintained replacement rather than pinning this release.
12%
Total Score
0
100
50
83
Packagist marks the entire package as abandoned and gives “not maintained any more” as the replacement text. Package-level abandonment is a severe dependency risk.
This is the only release, published on September 29, 2018, with no releases in the last 12 months. The long release gap materially increases abandonment risk.
The repository has had zero commits and zero active maintainers in the last three months. This confirms there is no recent maintenance activity to offset the old release history.
The linked repository is archived, with its last push on July 18, 2022. An archived source repository strongly indicates that future fixes and maintenance should not be expected.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a minor hygiene gap, while the build tooling provides some project structure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.