Usable with caveats: the package is licensed, clearly backed by its matching organization repository, and includes tests and a readable artifact. However, it has had no release or commit activity for over four years and provides no security policy, so maintenance should be verified before adoption.
58%
Total Score
75
100
71
83
The package has had no release in over four years, with five releases overall and none in the last 12 months. This is the strongest indication that maintenance may have stopped.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, which prevents this from being an automatic abandonment verdict but does not remove the maintenance concern.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible adoption provides no community-based compensation for the maintenance gap.
Composer is used for builds, but no security scanning tools are configured. The lack of scanning is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. For a package that publishes git history to Confluence and may handle project data, the absence of a documented reporting process is a real maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0.0 | ^5.0.0 | — | — |
guzzlehttp/guzzle Version ^7.4.0 | ^6.5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.