The repository includes tests and a changelog, and the package is MIT-licensed with no install-time scripts. It has no security scanning and uses three unpinned workflow actions, leaving maintenance and build hygiene concerns.
42%
Total Score
25
70
75
The package has 82 releases, but its latest release was in May 2023 and it had no releases in the last 12 months. That long pause materially raises abandonment risk despite its earlier release history.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release activity having stopped in May 2023. The repository is not archived, but that does not compensate for the absence of recent work.
There were no new or merged pull requests and no issue activity in the last month. With no recent commits or releases, this provides no evidence of ongoing maintenance.
Composer is used as the build tool, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe by itself.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although it is less significant than the prolonged lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
psr/cache Version ^1.0|^2.0|^3.0 | — | — |
psr/container Version ^1.0 | — | — |
symfony/config Version ^4.4|^5.0 | — | — |
symfony/console Version ^4.4|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.