The repository has had no commits in the last three months, and the registry shows no releases in the last year. Workflow dependencies are all unpinned, adding avoidable maintenance risk.
20%
Total Score
75
71
67
Packagist marks the entire package abandoned and names ringcentral-php as its replacement, making this release unsuitable for a new dependency despite the otherwise established project.
The package has 41 releases and a long history, but it had no releases in the last 12 months; this supports the abandonment concern rather than offsetting it.
The repository recorded zero commits and zero active maintainers over the last three months, indicating that current maintenance has stopped or substantially stalled.
The linked repository name does not match ringcentral/php-sdk and its README does not mention the package, leaving some uncertainty about the package-to-repository relationship.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, though the organization backing and repository tooling provide some context.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ratchet/pawl Version ^0.4.1 | — | — |
pubnub/pubnub Version ^4.7.0|^6.0 | — | — |
guzzlehttp/psr7 Version ^2.1.0 | — | — |
guzzlehttp/guzzle Version ^6.3.3|^7.4.1 | — | — |
symfony/event-dispatcher Version ^2|^3|^4|^5|^6|^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.