The source still includes tests, a changelog, and a matching README, and the MIT licensing is clear. Its tooling has no security scanning or security policy, leaving little evidence of ongoing oversight.
15%
Total Score
0
63
83
Packagist marks the entire package abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
Only five releases were published, and none occurred in the last 12 months; the latest release was about 10 years ago, showing prolonged release abandonment.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive for years.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest oversight gap.
The repository has no security policy, reducing transparency about how vulnerabilities would be reported or handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
doctrine/cache Version ^1.4 | — | — |
guzzlehttp/guzzle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.