Good documentation, clear licensing, repository tests, and no install-time scripts support adoption. However, the project has had no registry release since May 2022, no recent commits, and no security policy or scanning.
58%
Total Score
75
100
83
83
The package has made 5 releases, but none in the last 12 months and the latest was May 2022, indicating several years without a registry update. The stable version history is useful, but this materially raises abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the old latest release, this is concrete evidence of weak current maintenance capacity.
The repository has 0 stars, forks, and watchers, providing no supporting evidence of an active user or contributor community. Popularity is only supporting evidence, so this lowers confidence in project backing rather than determining the verdict alone.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools are present. The missing scanning is a hygiene concern for a package with otherwise limited recent activity.
The repository has no security policy. This weakens the project's vulnerability-reporting transparency, particularly because the package processes external media files, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version ^1.0 | — | — |
evenement/evenement Version ^3.0 || ^2.0 || ^1.0 | — | — |
alchemy/binary-driver Version ^1.5 || ~2.0.0 || ^5.0 | — | — |
neutron/temporary-filesystem Version ^2.1.1 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.