Unfit to use for a new dependency: the package is deprecated and its repository is archived. It has clear documentation, tests, and a stable release, but no release or commit activity for nearly four years means there is no credible ongoing maintenance.
18%
Total Score
50
100
50
83
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe adoption risk because future maintenance and compatibility are not expected.
The package has 17 releases and a historically regular median interval of about 64 days, but it has had no release in nearly four years. The long current gap outweighs the earlier release history.
The repository recorded no commits and no active maintainers in the last three months. This confirms the abandonment indicated by the archived repository and deprecated registry status.
The linked source repository is archived, and its last push was nearly four years ago. Archiving directly indicates that active development has ended.
The repository has no published security policy. This is a transparency gap, but it is secondary to the stronger evidence that the project is already deprecated and archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
platformsh/config-reader Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.