The repository is unarchived, clearly matches the package, and includes a usable README. Its ten runtime dependencies and lack of automated security scanning increase upkeep burden.
62%
Total Score
50
50
88
88
Ten runtime dependencies, including queue, cloud, process, and messaging integrations, create a relatively broad upkeep surface. The profile is understandable for the package's advertised functionality but increases maintenance burden.
The registry namespace and repository are owned by the same individual account, so ownership is internally consistent, but there is no organization backing shown to provide redundancy.
The package has 23 releases since 2015, but none in the last 12 months and the latest registry release was in January 2022. This materially raises abandonment risk despite its established history.
There were no commits and no active maintainers in the measured three-month period. This conflicts with the more recent repository push and still leaves current development capacity uncertain.
Composer build tooling is present, but no security-scanning tools were detected. For a package handling queues, cloud services, and process execution, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
opis/closure Version ^3.6 | — | — |
aws/aws-sdk-php Version ^3.133 | — | — |
duccio/apns-php Version =1.0.1 | — | — |
symfony/process Version >=4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.