The source repository includes tests, release notes, and a stable version, while the package has a simple dependency profile. Its organization-backed repository is not archived, but the release is withdrawn in favor of a replacement and the project has had no recent development.
18%
Total Score
50
69
50
The package is explicitly marked abandoned on Packagist, with digitickets/phpunit-errorhandler named as its replacement. This directly makes adopting the assessed package unsuitable despite other healthy metadata.
The latest release was on September 6, 2018, and there were no releases in the last 12 months. The long gap indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this is strong evidence of abandonment risk.
The package defines post-install and post-update Composer scripts. These add installation complexity and warrant caution, although no evidence here shows that the scripts are harmful.
Composer is used as the build tool, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not a decisive risk by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.