The README, tests, MIT declaration, and single runtime dependency provide a usable foundation. However, the last release and repository activity are about eight years old, with no recent commits or issue progress, alongside missing security tooling and policy.
18%
Total Score
50
100
64
75
Packagist marks the entire package as abandoned, with no replacement identified. Package-level deprecation is a severe adoption risk even though the specific release is not separately withdrawn.
The latest release was published about eight years ago, and there have been no releases in the last 12 months. This indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long maintenance gap rather than showing an isolated release pause.
There were no new or closed issues or pull requests in the last month, while three issues and one pull request remain open. This suggests little current project attention.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance weakness, though it does not outweigh the package-level abandonment evidence by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
victoire/victoire Version ~2.2 | ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.