The package includes tests, a substantial README, a matching MIT license, and no install-time scripts. Its single-maintainer ownership and lack of security scanning add modest transparency concerns.
58%
Total Score
50
81
75
The latest release was over six years ago, with no releases in the last 12 months. Although the package had 10 releases and a previously regular cadence, this strongly suggests it is no longer actively maintained.
Only one registry publisher is listed. Because this is a user-owned project rather than an organization-backed repository, the thin publisher base provides little redundancy if the maintainer stops responding.
The repository recorded no commits and no active maintainers in the last three months, consistent with the registry's long release gap. The repository is not archived, but there is no observed recent maintenance to offset the inactivity.
There were no new or closed issues or pull requests in the last month, while 10 issues and 4 pull requests remain open. This indicates unresolved project activity rather than active upkeep.
Composer build tooling is present, but no security scanning tools were detected. That limits evidence of ongoing dependency and source review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.2 | — | — |
guzzlehttp/guzzle Version ^6.3 || ^7.0 | — | — |
zeptech/annotations Version ^1.1 | — | — |
codeception/codeception Version ^2.4 || ^3.0 || ^4.0 | — | — |
justinrainbow/json-schema Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.