The repository still has tests, a changelog, release notes, and a clear MIT license. Its workflow uses four unpinned actions, adding maintenance hygiene risk.
52%
Total Score
50
86
67
The package has had no registry release in more than four years, despite 16 releases overall; this is meaningful evidence of possible abandonment.
There were no commits and no active maintainers in the measured three-month period, reinforcing the concern that development has stopped.
There were no new or closed issues or pull requests in the measured month, with 10 issues and 3 pull requests remaining open; this suggests limited ongoing maintenance.
The repository has no security policy, leaving disclosure and response expectations undocumented; this is a transparency gap, but not a severe standalone risk.
Version v0.8.1 is a stable, non-prerelease version, but the 0.x major line indicates a less mature compatibility commitment than a 1.x release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.4|^5.1 | — | — |
klaussilveira/gitter Version dev-php-semver-checker | — | — |
tomzx/php-semver-checker Version ^0.15.1 | — | — |
vierbergenlars/php-semver Version ^3.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.