Clear documentation, tests, licensing, and a small dependency set reduce adoption friction. The project shows no maintenance activity since 2015 and has little community activity, while the missing security policy leaves transparency weaker.
42%
Total Score
25
100
78
75
The latest release was published in September 2015, with no releases in the last 12 months despite the package being over 11 years old. This is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the release history showing that development stopped years ago.
There were no new or closed issues or pull requests in the last month. Combined with the old repository state, this provides little evidence of an active support community.
The repository has only 2 stars and no forks, so there is little visible community adoption or backup interest if maintenance is needed.
Composer is used as a build tool, but no security scanning tool is reported. The missing scanning is a modest hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.