The package is documented and has a stable MIT declaration, but its deployment tooling carries a broad runtime dependency set. The linked repository does not identify the package in its README, making ownership less clear.
35%
Total Score
50
50
75
75
This is the only release, published over 9 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for deployment tooling.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The package declares 12 runtime dependencies, including several analysis and testing tools such as PHPUnit, PHPMD, and PHP_CodeSniffer. This broad runtime surface increases maintenance and compatibility burden for a deployment utility.
The repository name does not match the package name and its README does not mention the package. Although the organization backing is consistent, the package-to-repository relationship is still less transparent.
Composer and Phing provide build tooling, which is a positive sign for project structure, but no security scanning tools are present. The tooling evidence does not offset the maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phing/phing Version ^2.11 | — | — |
phpmd/phpmd Version ^2.2 | — | — |
phploc/phploc Version ^2.1 | — | — |
phpunit/phpunit Version ^4.7 | — | — |
pear/archive_tar Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.