The BSD-3-Clause license, clear README, and organization ownership make the small utility easy to inspect and adopt. It has no install-time scripts, but limited project hygiene leaves little support if compatibility problems arise.
42%
Total Score
83
70
75
The package has only one release, published about 9 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
Four issues remain open, while there were no new or closed issues and no pull-request activity in the last month. This suggests unresolved maintenance needs and little current engagement.
The repository is not archived, which preserves a path for maintenance, but its last push was about 7 years ago and does not offset the stale release history.
No security policy is present. For a small utility this is a transparency gap rather than a severe risk, but it provides no documented route for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^3.3 | — | — |
composer/composer Version ^1.5 | — | — |
silverstripe/vendor-plugin Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.