Risky to adopt: this package has had only one release, remains prerelease, and shows no repository commits or issue activity since August 2022. It is clearly documented and not deprecated or archived, but the long-standing lack of maintenance makes future fixes uncertain.
38%
Total Score
33
100
75
75
The package has only one release, published about four years ago, with no releases in the last 12 months. That leaves little evidence of sustained maintenance or release maturity.
The repository recorded zero commits and zero active maintainers over the last three months, while its last push was about four years ago. This is the strongest evidence of abandonment risk.
The package and repository are owned by the same individual account. That provides direct ownership alignment but no organizational backing to compensate for the thin maintenance history.
There have been no new or closed issues or pull requests in the measured month, and no issues are currently open. This is consistent with a dormant project and provides no evidence of active support.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a transparency gap, though it is less significant than the documented maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version 1.0.x-dev | — | — |
psr/http-factory Version 1.0.x-dev | — | — |
psr/simple-cache Version 3.0.x-dev | — | — |
spatie/url-signer Version dev-main | — | — |
jeremykendall/php-domain-parser Version dev-develop | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.