It includes tests, release notes, and clear usage documentation. The long pause in maintenance and weak workflow pinning raise ongoing upkeep concerns.
58%
Total Score
83
81
67
The package has only 3 releases and none in the last 12 months; its latest release was over four years ago. This is a meaningful maintenance concern, although the repository remains available and the release is stable.
There were 0 commits and 0 active maintainers in the last three months, consistent with a project that has been inactive for over four years. This raises abandonment and compatibility risk.
Composer build tooling is present, but no security-scanning tools were detected. For a small package this is a modest transparency and maintenance gap, not a severe risk.
The linked repository is not archived, but it was last pushed over four years ago. The lack of archival is positive, while the old push date reinforces the maintenance concern.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.5 | — | — |
friendsofphp/php-cs-fixer Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.