It has no license, README, tests, changelog, or security policy, which leaves adoption and maintenance expectations unclear. The package and repository are structurally coherent, but there has been no release or commit activity for about 9 years, making abandonment the main concern.
32%
Total Score
0
58
100
The latest release was published on October 2, 2016, and there have been no releases in the last 12 months. About 9 years without a release is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, while its last push was in 2016. This confirms that the long release gap reflects inactive maintenance rather than merely a stable release cadence.
No registry license declaration, license file, or repository license file was detected. Without licensing terms, depending on the package creates legal and redistribution uncertainty.
The artifact has no README, tests, or changelog, and the repository also reports none. Missing tests and changelog can be normal for packaging, but the absent README leaves consumers without basic integration guidance.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
platform/foundation Version >=2.0 <5.0 | — | — |
cartalyst/composer-installers Version 1.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.