The package has clear documentation, repository tests, an MIT license, and no install-time scripts. Organization backing and a matching repository improve traceability, but do not offset the maintenance concern.
38%
Total Score
50
71
The latest release was published in January 2016, with no releases in the last 12 months; this is strong evidence of abandonment despite 11 historical releases.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and materially increasing abandonment risk.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance gap rather than a decisive risk.
The assessed version is still a beta release, and all recent releases are prereleases, leaving the package without a stable release line after years without updates.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
ramsey/uuid Version ^2.8 | — | — |
puli/discovery Version ^1.0-beta9 | — | — |
webmozart/glob Version ^4.0 | — | — |
webmozart/json Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.