The package includes a substantial README, extensive tests, and a source repository that clearly matches the package. Its CI workflow is complete but uses two unpinned actions, adding a modest reproducibility concern.
12%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement named. This is a severe warning against taking a new dependency on the release.
The package has had no releases in over four years despite 16 historical releases. That long release gap is consistent with an abandoned dependency.
The repository recorded no commits and no active maintainers in the last three months. Combined with the abandoned registry status and archived repository, this indicates no current maintenance capacity.
The linked repository is archived; its last push was in October 2024, nearly two years before collection. Archived source substantially increases abandonment and support risk.
The repository has no security policy. This is a transparency gap, though it is secondary to the stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2.3 | — | — |
symfony/yaml Version ^4.4 | — | — |
guzzlehttp/psr7 Version ^1.4.1 | — | — |
guzzlehttp/guzzle Version ^7.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.