It has a clear MIT license, tests in the repository, and security scanning. The source repository is otherwise inactive and lacks a security policy, while workflow dependencies are unpinned.
8%
Total Score
0
50
75
The package resembles the much more established vimeo/psalm and is flagged as borrowing that identity, creating a significant risk that consumers could select the wrong package.
Packagist marks the package as abandoned at package scope and points consumers to erunion/mill, making this release unsuitable as the maintained dependency path.
The package has 91 releases, but its latest release was July 1, 2020 and it had no releases in the last 12 months, indicating prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing that development has stopped.
The linked repository is archived, with its last push on September 2, 2021; archived source is a severe abandonment risk for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cocur/slugify Version ^4.0 | — | — |
pimple/pimple Version ^3.0 | — | — |
gossi/docblock Version ^2.0 | — | — |
composer/semver Version ^3.0 | — | — |
symfony/console Version ^3.2 || ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.