It has a clear MIT license, tests, and a repository that matches the package. Its 0.x status, sparse release history, inactive development, and unpinned workflow actions add adoption and maintenance concerns.
18%
Total Score
0
71
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a dependency on this release.
The repository recorded zero commits and zero active maintainers in the last three months; its last push was about eight months ago. That indicates a meaningful abandonment risk.
The package has only seven releases over about two years, with two releases in the last twelve months and a median interval of about 77 days. This is limited but not inherently unhealthy; combined with current inactivity, it supports caution.
The repository has no security policy. This is a transparency gap, though it is secondary to the package's abandonment status.
Version 0.5.1 is not a stable-major release, so consumers may face compatibility changes before a 1.0 release. The absence of prereleases is a modest compensating signal, but the package remains immature.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.4|^7.0 | — | — |
symfony/process Version ^6.4|^7.0 | — | — |
nategood/httpful Version ^1.0 | — | — |
webmozart/assert Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.