The package has tests, a useful README, an MIT license, and only two runtime dependencies. It lacks a security policy and security scanning, leaving limited evidence of ongoing security upkeep.
42%
Total Score
25
100
79
50
This is the package's only release, published over 12 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, although the stable v1.0.0 version may indicate a small, finished component.
The repository recorded zero commits and zero active maintainers in the last 3 months, and its last push was about 10 years ago. This provides no evidence of current maintenance capacity.
There were no new or closed issues or pull requests in the last month, with no open work either. Combined with the lack of recent commits, this supports the conclusion that the project is inactive rather than actively maintained.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate for the package, while the missing scanning reduces evidence of ongoing security hygiene.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap, though it is less serious than the long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ~1.0 | — | — |
container-interop/container-interop Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.