The repository has had no recent commits, and the registry shows only one release since September 2022. The matching, organization-owned repository and repository license provide some transparency, but not enough evidence of active maintenance.
40%
Total Score
50
100
72
83
The package has only one release, published in September 2022, with no releases in the last 12 months. This is strong evidence of low maintenance activity for a dependency intended for ongoing use.
There were no commits and no active maintainers in the last three months. This materially increases abandonment risk, despite the repository not being archived.
Seven issues remain open, with no issues or pull requests created or closed in the last month. Combined with the lack of recent commits, this suggests limited ongoing project response.
The repository has zero stars and one fork, offering little supporting evidence of broad adoption. Popularity is only supporting evidence, so this is a minor concern rather than a decisive risk.
The repository uses Composer, appropriate for this PHP package, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11 | — | — |
aws/aws-sdk-php Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.