Its MIT license and concise setup README make the package understandable, but the missing security policy offers little additional assurance for a web integration. Choose an actively maintained alternative.
8%
Total Score
0
40
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry itself signals that development has ended.
This release is the package's only release, published over 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment rather than an actively maintained stable package.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with its archived state and leaving no evidence of ongoing maintenance.
The linked repository is archived and was last pushed in July 2015, so it is no longer maintained through its source repository.
Composer post-install and post-update scripts execute package-defined behavior during dependency operations, increasing the review surface. No provided signal shows that this execution surface is actively maintained or security-reviewed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.0 | — | — |
symfony/http-foundation Version ^2.7 | — | — |
incenteev/composer-parameter-handler Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.