The package has clear licensing, a substantial README, tests, a changelog, and organizational backing. Its maintenance appears abandoned, so new fixes and compatibility work are unlikely.
46%
Total Score
50
71
50
The package has 41 releases and a history dating to 2012, but it has had no release in over six years and none in the last 12 months. This strongly raises abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the registry's long release gap. This is strong evidence of inactive maintenance.
Composer is used for the build, but no security scanning tools are present. The missing scanning is a hygiene gap, not by itself evidence that the package is unsafe to depend on.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. This matters more for a library with ongoing maintenance needs, which the activity signals do not demonstrate.
The assessed release is not marked prerelease, but the registry reports version 0.13.1 as latest while the assessed version is v0.15.1, creating uncertainty about version freshness and registry consistency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version ^1.0 | — | — |
evenement/evenement Version ^3.0 || ^2.0 || ^1.0 | — | — |
alchemy/binary-driver Version ^1.5 || ~2.0.0 || ^5.0 | — | — |
neutron/temporary-filesystem Version ^2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.