The package has a very small audience and no automated security scanning. Repository tests, a changelog, stable versioning, and organizational backing provide some support, but not enough to offset the maintenance gap.
48%
Total Score
75
75
100
Only four releases exist, with none in the last 12 months; the latest registry release was in July 2020, roughly six years ago. This is a substantial abandonment concern, despite the linked repository being recently pushed.
The published README is extremely short at 13 characters, which gives consumers little integration guidance. Repository tests and a changelog compensate for project-level documentation gaps, but not for the thin package-facing README.
The repository recorded zero commits and zero active maintainers in the last three months. Although repository metadata shows a recent push, the measured development activity remains absent.
The repository has 1 star, 0 forks, and 1 watcher, providing little evidence of a broad user or contributor community. Low popularity is supporting caution rather than a verdict by itself.
Composer is used as a build tool, but no security-scanning tool is configured. For a broad library with 19 runtime dependencies, this is a meaningful maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/intl Version * | — | — |
symfony/yaml Version * | — | — |
google/apiclient Version ^2.4 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.