The package has tests, a README, and organizational ownership. Its pre-1.0 release line has not advanced since December 2022, while recent repository activity is absent, so pinning this version carries maintenance risk.
60%
Total Score
75
79
50
The package has had no release in roughly three years: its latest release was December 8, 2022, despite four releases overall. This materially raises abandonment and compatibility risk.
There were zero commits and zero active maintainers in the three months measured. That is a concrete sign of currently limited maintenance capacity, partially offset by the repository push in February 2025.
The project uses Composer for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. The package's tests and organizational backing provide some context, but do not replace a published process.
The latest version remains below 1.0, so compatibility guarantees are limited. It is not marked as a prerelease, which provides some compensation but does not remove the maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/iter Version ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.