The package is clearly licensed, has a matching source repository, and includes practical documentation plus release notes. Its limited adoption, unresolved issues, absent security tooling, and very small maintainer base leave little evidence of ongoing support.
40%
Total Score
33
79
75
The package has had no releases in the last 12 months, and its latest release was in July 2021 despite being over five years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers over the last three months, reinforcing the long release gap rather than showing current maintenance.
Only one registry maintainer is listed, leaving limited visible continuity if that person stops maintaining the package. The repository is user-owned, so there is no organizational backing shown to offset this.
Three issues remain open, with no issues or pull requests opened, closed, or merged in the last month. This is consistent with an inactive project, though the issue count is small.
Composer is used for builds, but no security-scanning tooling is present. That reduces transparency around automated security checks, although it is not evidence of a specific defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.3 | — | — |
samsara/mason Version ^0.2 | — | — |
symfony/console Version ^v5.3 | — | — |
opis/json-schema Version ^2.0 | — | — |
hassankhan/config Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.