The repository includes tests and the package declares MIT licensing. No commits or releases have appeared for more than 8 years, making ongoing maintenance unlikely; one maintainer and no security policy add resilience concerns.
38%
Total Score
25
67
50
The package has had no release in more than 8 years and only four releases overall, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the stable version format.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and leaving little evidence of current maintenance.
Only one registry maintainer is listed, creating a thin publishing base and increasing continuity risk if that person becomes unavailable.
The linked repository has no security policy, so users have no documented channel or process for reporting vulnerabilities. The small, inactive project provides no compensating evidence of security response capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.2 | — | — |
symfony/cache Version >=3.4 | — | — |
monolog/monolog Version ^1.23 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
symfony/http-foundation Version >=3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.