The package includes tests, a README, and a declared MIT license. Single-person ownership and the repository/package name mismatch add uncertainty about support and provenance.
38%
Total Score
25
70
83
The package has had no release in over 10 years: its latest release was in May 2016, with only two releases overall. This is strong evidence of abandonment for a dependency, despite the stable 1.0.0 version.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was over 9 years ago. The existing source tree provides context but does not offset the absence of recent maintenance.
Only one registry account has publishing access, leaving little visible publishing redundancy. This is a secondary concern because the project is user-owned rather than organization-backed.
The linked repository name does not match the package name and its README does not mention the package. That weakens confidence that the repository is the intended project source rather than an unrelated or loosely related location.
The repository has no security policy. For an old package with no recent activity, the absence of a documented way to report vulnerabilities adds a transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
patchwork/utf8 Version ~1.2 | — | — |
doctrine/common Version ^2.5 | — | — |
guzzlehttp/guzzle Version ^6.0 | — | — |
symfony/http-kernel Version ~2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.