The MIT license and matching repository support basic transparency, and the package has no install-time scripts. Its small project footprint offers little evidence of ongoing maintenance, so pinning this old release carries meaningful abandonment risk.
40%
Total Score
0
64
100
The package has had no releases in about eight years; its six releases were concentrated near the initial 2017–2018 launch. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of current maintenance.
The published artifact has no README, while tests and a changelog are not expected in the package artifact. For a client library, the missing consumer documentation is a real usability and transparency gap.
The repository has 1 star, 0 forks, and 1 watcher, providing little supporting evidence of community use or review. Popularity is only supporting evidence, so this does not determine the score alone.
Version v0.6.2 is not a prerelease, but it remains below a stable major version, offering weaker maturity evidence for a package that has not evolved since 2018.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mnapoli/silly Version ^1.7 | — | — |
php-di/php-di Version ^5.4 | — | — |
symfony/dotenv Version ^3.4 | — | — |
symfony/finder Version ^3.4 | — | — |
google/protobuf Version v3.5.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.