Its MIT license, tests, and matching repository support transparency. The absence of recent commits or releases, plus package-level abandonment, makes maintenance and compatibility too uncertain.
18%
Total Score
50
67
50
Packagist marks the entire package as abandoned and provides no replacement, directly signaling that new dependencies should not be adopted.
The latest release was in May 2017, with no releases in the last 12 months despite the package being more than nine years old, indicating prolonged abandonment.
There were zero commits and zero active maintainers in the last three months, consistent with the package's long period without releases and reinforcing the abandonment risk.
The repository has only 5 stars and 7 forks, offering little supporting evidence of broad community maintenance; this is secondary to the stronger abandonment signals.
The repository uses Composer, but no security scanning tools are reported; this is a hygiene gap rather than a decisive risk for the health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
vdb/php-spider Version ^0.2 | — | — |
symfony/process Version ^3.1 | — | — |
symfony/symfony Version ^2.7||^3.0 | — | — |
snc/redis-bundle Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.