The stable major release and substantial test coverage add useful reassurance. However, six years without a release or commit activity makes this a risky dependency; verify that its older framework stack still fits your project.
42%
Total Score
67
50
75
75
The package has 11 releases, but none in the last six years; its latest registry release was in January 2020. This is strong evidence of abandonment risk despite a historically active early cadence.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating that maintenance has effectively stopped.
The package declares 10 runtime dependencies, including testing, mocking, code-coverage, linting, and analysis tools. That unusually broad runtime profile increases maintenance and compatibility burden.
The repository name does not match the package name and its README does not mention the package. Although subpackages can use a related repository, this leaves uncertainty about whether the repository directly represents this release.
Composer build tooling is present, but no security-scanning tooling is reported. The missing scanning is a hygiene gap, not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^2.7 | — | — |
msbios/msbios Version ^2.0 | — | — |
mockery/mockery Version ^1.2 | — | — |
pdepend/pdepend Version ^2.5 | — | — |
badoo/soft-mocks Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.