It has a clear MIT license, tests, a substantial README, organization ownership, and no install-time scripts. The package offers little evidence of ongoing maintenance, so future PHP or dependency compatibility may require taking on ownership.
45%
Total Score
67
81
75
The package has had only two releases, both in October 2017, with no releases in the last 12 months. This strongly limits evidence that the published dependency is maintained for current consumers.
The repository recorded zero commits and zero active maintainers in the last three months, despite its last push being in June 2021. That indicates a substantial maintenance gap for a package consumers may still need to update.
There were no new or closed issues or pull requests in the last month, while two issues and two pull requests remain open. This is consistent with low project activity, though the open items alone do not establish abandonment.
The repository uses Composer and Make, which supports repeatable project operations, but it reports no security scanning tools. That leaves less automated evidence of security maintenance.
The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although it is a secondary concern compared with the package's long release and commit gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpociot/botman Version ^1.5 | — | — |
guzzlehttp/psr7 Version ^1.4.2 | — | — |
vlucas/phpdotenv Version ^2.2 | — | — |
guzzlehttp/guzzle Version ^6.2.3 | — | — |
symfony/event-dispatcher Version ^2.7|^3.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.