Usable with caveats, but maintenance appears effectively dormant: the latest release was nearly seven years ago and the repository has had no recent commits. It has matching organization backing, tests, a license, and a modest dependency set, so it is not unfit, but verify compatibility before adopting it.
58%
Total Score
75
100
70
50
The package has five releases, but none in the last 12 months and its latest release was nearly seven years ago. This long period without a release materially raises abandonment and compatibility risk.
The package runs post-install and post-update scripts, adding installation-time behavior that deserves review before adoption. No other provided signal shows that these scripts are necessary or harmless.
There were no commits and no active maintainers in the last three months, consistent with the repository's old last-pushed date. This is strong evidence that fixes and compatibility updates may not arrive promptly.
The repository is not marked archived, which is a positive, but it was last pushed nearly six years ago. The unarchived status does not compensate for the prolonged lack of visible maintenance.
The repository has no security policy. For a small, dormant package this leaves vulnerability-reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpgears/cqrs-async Version ~0.3 | — | — |
queue-interop/queue-interop Version ~0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.