Documentation, tests, release notes, licensing, and organizational ownership provide a solid foundation. However, no release has appeared in more than 10 years, and recent repository activity is absent, so maintenance risk is substantial.
58%
Total Score
50
100
83
88
The package has 25 releases and a historical median interval of about 24 days, but its latest release was over 10 years ago and there were no releases in the last 12 months. The long release hiatus materially raises abandonment and compatibility risk.
There were zero commits and zero active maintainers during the last three months. Combined with the long release hiatus, this is strong evidence that active maintenance has effectively stopped.
The repository has 48 open issues and 11 open pull requests, but recorded activity shows no new or closed issues or pull requests in the last month. This suggests unresolved maintenance demand.
Composer is used for builds, which fits the PHP package. No security scanning tools were detected, leaving a modest repository hygiene gap, though this is not a severe dependency-health risk by itself.
The repository has no security policy, making vulnerability reporting and response expectations less transparent. This adds a maintenance and disclosure gap, but does not independently make the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
guzzle/guzzle Version ~3.8 | — | — |
mikemccabe/json-patch-php Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.