Usable with caveats: this is a mature, well-structured package with a clear repository, tests, releases, and a permissive license. However, it has had no registry releases or repository commits for about 2 years and 6 months, so future fixes and compatibility work are uncertain.
65%
Total Score
67
100
89
80
The package has 19 releases over more than 12 years, but none in the last 12 months and the latest release was about 2 years and 6 months ago. This indicates materially slowed maintenance despite a historically established release record.
There were no commits and no active maintainers in the last 3 months, consistent with a repository that has been inactive since the latest release about 2 years and 6 months ago. This is the main maintenance and abandonment concern.
There are only 5 open issues and no recent issue or pull-request activity. The small backlog is not severe, but the lack of recent responses provides little evidence of active support.
Composer, Phing, and Box are used for building, showing established project tooling. No security scanning tools were detected, which is a hygiene gap, but it is less decisive than the demonstrated build setup.
The repository has no security policy. This reduces transparency about vulnerability reporting and maintenance expectations, although it is a secondary concern for the overall dependency decision.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ~1.7||~2.0||~3.0 | — | — |
symfony/console Version ~3.4||~4.0||~5.0||~6.0 | — | — |
phpunit/php-file-iterator Version ~2.0||^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.