The BSD-3-Clause license, tests, and readable tree make the package transparent to inspect. There is no security policy or repository security scanning, so maintenance safeguards are limited.
52%
Total Score
0
71
75
The package has 22 releases and a short historical median interval, but it has had no releases in more than three years. That long gap materially weakens confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release gap and providing no evidence of current development.
Composer is used for builds, but no security scanning tools were detected. This is a modest maintenance and assurance gap rather than evidence that the package is unsafe.
The linked repository is not archived, although its last push was more than three years ago. The unarchived state is positive but does not offset the lack of recent activity.
The repository has no security policy. That limits transparency around vulnerability reporting and response, especially for a package with weak recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tasoft/config Version ^8 | — | — |
tasoft/tools-path Version ^1.5 | — | — |
tasoft/event-manager Version ^1 | — | — |
tasoft/service-manager Version ^2 | — | — |
symfony/http-foundation Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.