It includes tests, a matching source repository, clear Apache-2.0 licensing, and no install-time scripts. The project is not archived, but its old ecosystem and limited recent activity make long-term support uncertain.
43%
Total Score
50
50
81
75
The package has 35 releases but none in the last 12 months; its latest release was in June 2017, roughly 9 years ago. This is strong evidence that maintenance has stopped.
There were zero commits and zero active maintainers in the last 3 months. Combined with the old latest release, this indicates a sustained lack of visible maintenance.
Ten runtime dependencies, including framework, media-processing, and extension requirements, create meaningful integration and maintenance surface. No dependency-specific failure is shown, so this is only a modest concern.
The repository has two open issues and no new or closed issues or pull requests in the last month. This supports the broader picture of limited current project activity.
Composer is used for builds, but no security-scanning tool was detected. The missing scanner is a hygiene gap, while the long period without maintenance is the larger concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alav/composer-assets Version ~1.0.0 | — | — |
php-ffmpeg/php-ffmpeg Version ~0.6.1 | — | — |
doctrine/data-fixtures Version ~1.2.0 | — | — |
flowjs/flow-php-server Version ~1.0.0 | — | — |
symfony/monolog-bundle Version ~2.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.