The repository still has tests, a clear MIT license, and matching package metadata. Nearly ten years without a release or recent commits, plus no security policy or scanning, makes future maintenance uncertain.
42%
Total Score
63
78
83
The latest release was in November 2016, with no releases in the past 12 months; nearly ten years without a release is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the past three months, while the last repository push was in 2016; this is strong evidence that fixes and maintenance are unlikely.
There are no open issues or pull requests and no issue or pull-request activity in the past month; combined with the old release history, this is consistent with an inactive project.
The repository has zero stars and one fork, indicating a very small user and contributor footprint; popularity is only supporting evidence, but this adds to the maintenance concern.
Composer build tooling is present, but no security-scanning tools were detected; that weakens ongoing security transparency without proving a defect in the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.2 | — | — |
pimple/pimple Version ~1.0 | — | — |
knplabs/gaufrette Version 0.2.* | — | — |
webvariants/babelcache Version ~2.0 | — | — |
sallycms/composer-installer Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.