Tests, release notes, clear licensing, and organizational ownership support dependable packaging. The absent security policy and scanning leave less transparency for responding to future issues.
55%
Total Score
67
100
88
50
The package has 107 releases since December 2015, but none in the last three years; that long gap is a meaningful abandonment concern despite its historically active cadence.
There were no commits and no active maintainers in the last three months, consistent with the multi-year release gap and indicating a real maintenance risk.
There was no new or closed issue activity in the last month, while five pull requests remain open; this suggests limited recent project attention.
Composer is used for builds, but no security scanning tools are configured, leaving automated security coverage absent.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/stempler-bridge Version ^1.0 | ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.