The package has a usable README, tests, release notes, and no install-time scripts, while its repository remains available. The limited security tooling and single published release provide little reassurance for long-term maintenance.
43%
Total Score
100
50
75
This is the sole release, published in May 2015, with no releases in the past 12 months; that is strong evidence of abandonment risk for a dependency.
The repository is not archived, but its last push was in October 2015, confirming that source activity has been inactive for roughly 11 years.
The project uses Composer and Make, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap for an old package.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a secondary concern because the larger risk is the prolonged lack of activity.
The latest version is v0.1 and is not a stable major release, which adds maturity uncertainty alongside the absence of subsequent releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~1.9 | — | — |
cocur/vale Version ~0.2 | — | — |
plumphp/plum Version ~0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.