The repository has had no commits for over three years, and its package reference does not match the linked project. It has a license, tests, and release notes, but those positives do not offset the maintenance and identity concerns.
18%
Total Score
50
58
Packagist marks the entire package as abandoned and names oneago/arcturus-project as the replacement, making this release unsuitable for a new dependency.
The package has had no releases in the last 12 months; its latest release was over three years ago despite a previously regular median interval of about 15 days.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating weak ongoing maintenance.
The linked repository name does not match this package and its README does not mention the package, so the source-package relationship is not clearly established.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
robmorgan/phinx Version ^0.12 | — | — |
vlucas/phpdotenv Version ^5.3 | — | — |
symfony/twig-bridge Version ^6.1 | — | — |
oneago/arcturus-core Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.