The repository is structured, tested, licensed, and has a security policy. However, maintenance evidence is weak for this release, and the package is marked abandoned on Packagist.
38%
Total Score
50
67
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a serious adoption and maintenance warning even though the linked repository is not archived.
The package has made no release in nearly seven years and has had zero releases in the last 12 months. Its long history and 18 total releases show maturity, but do not offset the current release gap.
The repository recorded zero commits and zero active maintainers in the last three months. This supports the concern that the published package is no longer actively maintained.
Both workflows were analyzed without high-confidence findings or unsafe triggers, but all 11 action references are unpinned. That leaves avoidable build reproducibility and supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
symfony/yaml Version ^2.0.5 || ^3.0 || ^4.0 || ^5.0 | — | — |
symfony/config Version ^2.1 || ^3.0 || ^4.0 || ^5.0 | — | — |
symfony/console Version ^2.1 || ^3.0 || ^4.0 || ^5.0 | — | — |
guzzlehttp/guzzle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.