The README, changelog, release notes, and matching license make the project relatively transparent. Its small dependency set and lack of install scripts reduce adoption friction, but ongoing maintenance evidence is weak.
40%
Total Score
33
100
75
75
The package has had no release in more than 11 years, with only four releases overall and none in the last 12 months. This is strong evidence that maintenance has stopped.
There were zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. The repository's last push was also more than 6 years ago.
Only one registry publishing maintainer is listed, and project backing identifies an individual owner rather than an organization. For a small project this is understandable, but it leaves little visible maintenance redundancy.
No issues or pull requests were opened or merged in the last month, while three issues and one pull request remain open. This adds evidence of limited ongoing attention.
Composer is used as a build tool, which is appropriate for this package, but no security-scanning tool is configured. That is a modest hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version 2.* | — | — |
symfony/process Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.