The repository is small and the package is easy to inspect. Its release and commit history point to long-term abandonment, despite tests, licensing, and a security policy.
42%
Total Score
25
100
70
100
The latest release was over six years ago, with no releases in the last 12 months and only four releases overall. That is strong evidence of abandonment for a dependency that may need current API support.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long period without a release. This leaves little evidence of ongoing maintenance capacity.
The repository is owned by an organization, which can provide backing beyond an individual maintainer. However, the provided activity signals show no recent work, so the organizational ownership does not remove the abandonment concern.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was over six years ago and does not offset the inactive release and commit history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
gmostafa/php-graphql-client Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.