It includes a license, README, changelog, security policy, and automated checks. Its large runtime dependency set and unpinned workflow references add maintenance and build-integrity concerns.
55%
Total Score
75
50
86
67
The package declares 40 runtime dependencies, including several internal and specialized libraries, creating a relatively large maintenance and transitive-risk surface.
Post-create, post-install, and post-update Composer scripts run during installation or updates, increasing operational complexity for consumers.
The package has had no release in over two years and none in the last 12 months, which points to slowing maintenance despite having 10 releases overall.
There were no commits and no active maintainers in the last three months, which weakens the evidence of ongoing maintenance even though the repository is not archived.
Version 0.4.4 is a stable, non-prerelease release, but it remains below 1.0, so compatibility expectations are less mature.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/xml Version ^2.0 | — | — |
league/csv Version ^9.0|^8.0 | — | — |
php-ai/php-ml Version >=0.8 | — | — |
league/climate Version >=3.4 | — | — |
symfony/finder Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.