Clear ownership, matching source, and a documented AGPL-3.0 license improve transparency. Maintenance has effectively stopped, so future compatibility and fixes are uncertain.
58%
Total Score
50
70
75
The package has 22 releases since 2016, but none in the last five years, indicating that maintenance has stopped for a substantial period.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long release gap and increasing abandonment risk.
Composer is used for the build, but no security scanning tools are present; this is a minor hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear, although this does not by itself show that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
swp/storage Version ^2.0 | — | — |
symfony/options-resolver Version ^4.2 | — | — |
symfony/expression-language Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.