It has a license, tests, a matching repository, and no install-time scripts. The organization-owned project is not archived or deprecated, but its small footprint and missing security policy leave little ongoing assurance.
42%
Total Score
50
71
75
The latest release was published about 9 years and 11 months ago, with no releases in the last 12 months; this is strong evidence of abandonment for a dependency.
The repository has had no commits or active maintainers in the last 3 months, and its last recorded push was about 9 years and 5 months ago. This is not offset by the repository merely remaining available.
The repository has only 5 stars and 2 forks, providing limited evidence of broad community review or support. Low popularity alone is supporting evidence rather than a decisive defect.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported; this is a secondary concern alongside the much older maintenance record.
Version 0.0.3 is not a stable-major release, so API compatibility may be less predictable; the package is nevertheless not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
prooph/common Version ^3.7 | — | — |
prooph/event-store Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.