Its BSD-3-Clause licensing, documented installation, and repository tests support adoption mechanics. The small dependency set and organization ownership help, but the missing security policy weakens transparency.
30%
Total Score
50
100
64
50
Only two releases were published, both nearly 13 years ago, with none in the last 12 months. This is strong evidence that the package is no longer actively maintained.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this indicates sustained abandonment risk.
There was no new issue or pull-request activity in the last month, with one issue still open. This is consistent with a largely inactive project.
Composer is used as a build tool, but no security scanning tools are reported. The missing scanning is a minor hygiene gap, not a standalone dependency blocker.
The repository is not archived, which is a modest positive, but its last push was in 2015 and does not offset the lack of current release activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.* | — | — |
twig/twig Version 1.* | — | — |
doctrine/dbal Version 2.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.