It includes a readable README, tests, a changelog, and release notes for this version. The repository has no security scanning or policy, and its only workflow uses an unpinned action, adding smaller maintenance and build-hygiene concerns.
15%
Total Score
50
100
57
67
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk because future maintenance and support are uncertain.
There were zero commits and zero active maintainers in the last three months. Together with the archived repository and absent recent releases, this indicates no current maintenance capacity.
The linked repository is archived and was last pushed on September 18, 2023, so it is no longer actively maintained. This strongly reinforces the package-level abandonment signal.
The package has a substantial history with 41 releases since July 2018, but it has had no release in roughly three years and none in the last 12 months. Earlier release history provides maturity evidence but does not offset the current standstill.
There were no new or closed issues or pull requests in the last month, while 8 issues and 3 pull requests remain open. This is consistent with an inactive project rather than ongoing support.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^2.0 || ^3.0 | — | — |
oxid-esales/oxideshop-ce Version ^v6.0.0 | — | — |
oxid-community/moduleinternals Version > 1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.