Risky to adopt: the package has not published a release in nearly nine years, and the repository has had no recent commit activity. It remains unarchived, clearly matches the package, and has a simple Composer setup, but maintenance evidence is too weak for a dependable dependency.
48%
Total Score
0
100
71
75
Only two releases were published, both in October 2017, with no release in nearly nine years. This is strong evidence of abandonment risk despite the stable 1.0 version.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the lack of current maintenance activity.
The repository has zero stars and forks and only one watcher, providing little external evidence of adoption or community support. Low popularity alone is not decisive, but it offers no compensation for the stale maintenance record.
The repository is not archived and was last pushed in June 2022, which is a modest positive, but that activity is still several years old and does not offset the absent recent maintenance.
No security policy is present, leaving vulnerability reporting guidance undocumented. This is a transparency weakness, although the repository is very small and has no recent workflow activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version ^2.7 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.