Its last release was over five years ago, and version 0.0.3 signals an immature project. The repository could not be found, so maintenance and provenance cannot be verified; the README and declared license are helpful but do not offset the risks.
12%
Total Score
50
Packagist marks the entire package as abandoned, with no replacement named. Package-level abandonment is a severe warning for a dependency.
The package has only three releases, and its latest release was over five years ago; there have been no releases in the last 12 months. This strongly indicates abandonment.
The latest version is 0.0.3 and is not a stable major release, which indicates limited maturity. No newer stable line is provided to compensate for this.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=9.5 <11.0.0 | — | — |
league/oauth2-server Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.