The small artifact provides little consumer guidance, and the project has no security policy or scanning support. Its maintenance evidence is too weak for a dependable modern dependency.
12%
Total Score
30
50
Packagist marks the entire package as abandoned, with no replacement named. Package-level abandonment is a severe dependency risk regardless of the repository's non-archived status.
This package has only one release, published about 12 years ago, with no releases in the last 12 months. That strongly indicates abandonment rather than an actively maintained stable project.
No license is declared, and neither the package artifact nor the linked repository contains a recognized license file. This leaves the terms for using the dependency unclear.
The published artifact has no README, so consumers receive little usage guidance for this command-line package. The absence of tests and a changelog is normal packaging practice and does not add risk by itself.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a modest hygiene gap rather than evidence of a direct dependency failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.