The README, MIT license, and exact-version release notes make the project easy to inspect and use. Maintenance has stopped for about two years, while its 26 runtime dependencies increase upkeep risk.
57%
Total Score
50
50
88
67
The package declares 26 runtime dependencies, including development and analysis tools such as PHPUnit, PHPStan, and security advisories, creating an unusually broad maintenance and compatibility surface.
The registry namespace and repository are owned by the same individual account, confirming ownership alignment but providing no organizational backing to compensate for the thin maintenance base.
The package has eight releases since October 2023, but none in the last 12 months and the latest release was about two years and five months ago, indicating stalled maintenance.
There were no commits and no active maintainers in the last three months, consistent with the roughly two-year release pause and raising abandonment risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
nyholm/psr7 Version ^1.3 | — | — |
symfony/yaml Version ^5.1 | — | — |
pimple/pimple Version ^3.3 | — | — |
psr/container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.