Clear licensing, tests, and a readable build guide help inspection. The source project has had no recent commits and the registry marks the package abandoned, leaving no active maintenance path.
15%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement listed. This is a severe dependency-maintenance risk because future fixes and support are unlikely.
The package has only three releases, all around September 2014, and none in the last 12 months. Nearly 12 years without a release strongly indicates abandonment for a maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and lack of ongoing maintenance.
The repository name does not match the package name and its README does not mention this package. That makes package ownership and release provenance less transparent, despite the linked repository being available.
The project uses Composer and Phing, which provides build structure, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, not a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.