Risky to adopt for new projects: the package has had no release in nearly 6 years and no repository commits in nearly 6 years. It is licensed, documented, tested, and backed by a matching organization-owned repository, but the lack of recent maintenance is a substantial liability.
45%
Total Score
50
50
81
75
The package has 25 releases, but its latest release was nearly 6 years ago and it had no releases in the last 12 months, indicating prolonged inactivity.
There were no commits and no active maintainers in the last 3 months, confirming that development activity has effectively stopped.
Ten runtime dependencies create a meaningful maintenance surface for an old PHP package, although the signal does not show that any dependency is currently broken or abandoned.
There are no open issues or pull requests and no recent issue or pull-request activity; this is consistent with a dormant project rather than evidence of active support.
The repository uses Composer, but it has no security scanning tools, leaving a transparency and maintenance gap for a package with no recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
psr/cache Version ^1.0 | — | — |
beberlei/assert Version ^2.6 | — | — |
php-http/httplug Version ^1.1 | — | — |
cache/void-adapter Version ^0.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.