The MIT license, readable documentation, release notes, and included tests provide useful transparency. The package has had no new registry release or recent repository commits, while security scanning and a security policy are absent.
40%
Total Score
25
67
50
This is the package's only release, published about nine years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the one-release history, this indicates a substantial abandonment risk.
The registry lists one maintainer. A single publisher is not inherently unhealthy for a user-owned project, but it leaves little visible publishing redundancy alongside the lack of recent activity.
The repository has one star, one fork, and one watcher. Low adoption is only supporting evidence, but it provides little additional confidence in maintenance or community support.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
eluceo/ical Version ^0.9.0 | — | — |
symfony/framework-bundle Version ~2.8|~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.