The README explains the package’s narrow purpose and usage, and its dependency set is small. Missing tests and security scanning leave little evidence of ongoing quality control.
5%
Total Score
0
100
44
75
The package borrows the identity of the much more established shalvah/upgrader, with borrows_lookalike_identity set to true. Consumers may have intended that established package instead.
Packagist marks the entire package as abandoned, with no replacement provided. That is a direct warning against taking a new dependency on this release.
The package has only one release, from August 2017, and none in the last 12 months. This provides strong evidence of abandonment rather than an actively maintained release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived status and lack of ongoing maintenance.
The linked repository is archived and was last pushed in February 2021, so it is no longer receiving normal maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.22 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.