The source has a useful README, documented MIT licensing, tests, and release notes for this version. Its Packagist entry is deprecated and the package has had no registry releases since January 2022, so use the replacement php-sage/sage instead.
20%
Total Score
75
67
50
Packagist marks the entire package as abandoned and names php-sage/sage as the replacement, making this release unsuitable for a new dependency despite the linked repository remaining available.
The package has made only 3 releases, all beginning in January 2022, with 0 releases in the last 12 months; this is strong evidence that the registry package is no longer maintained for consumers.
The package runs post-install and post-update Composer scripts, adding install-time execution surface that developers should account for when adopting an otherwise deprecated package.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing the lack of current maintenance even though the repository itself is not archived.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a secondary transparency gap rather than the main adoption blocker.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.