Usable with caveats: the package is clearly licensed, tested, and backed by an organization, but it has had no release or repository activity for over five years. Treat it as a maintenance-risk dependency, especially if you need ongoing fixes or compatibility updates.
58%
Total Score
50
100
75
75
The package has 12 releases since 2019, but none in the last five years; the latest release was over five years ago. This is strong evidence of an unmaintained release line despite its previously regular cadence.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long period since the last release. This substantially increases the risk that compatibility or defect fixes will not arrive.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap, while the long inactivity is the more significant concern.
The repository has no security policy, leaving no documented process for reporting vulnerabilities. This is a genuine but secondary concern for a small, inactive component.
Both analyzed workflows omit top-level token permissions, so their permissions are not explicitly constrained at the workflow level. No write permissions were observed, making this a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swoft/stdlib Version ~2.0.0 | — | — |
symfony/yaml Version ^4.3 | — | — |
vlucas/phpdotenv Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.