The package includes a README, repository tests, and a clear MIT license. Its source is not archived, but maintenance has stopped and the registry marks the package abandoned.
15%
Total Score
50
100
64
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe dependency-lifecycle warning for a new adoption.
The package has had no releases in the last 12 months, and its latest release was in March 2020 despite 39 historical releases. The long release gap indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed in November 2023, there is no evidence of current development.
The repository has no security policy. This is a transparency gap, though it is secondary to the package's explicit abandonment and stale release history.
The assessed version is not a prerelease, but the package remains on major version 0, so its API maturity is limited. This compounds the maintenance concerns rather than offsetting them.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
msgphp/domain Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.