The release includes tests, a README, and matching MIT licensing, with no install-time scripts or registry deprecation. Its workflow references are all unpinned, and the linked project does not identify this package by name, reducing transparency.
52%
Total Score
50
100
75
67
The package has 20 releases since March 2014, but its latest release was over 3 years ago and there were no releases in the last 12 months, indicating likely abandonment risk.
There were no commits and no active maintainers in the past 3 months, consistent with the release history's strong maintenance concern.
There was no issue or pull request activity in the past month, with one issue still open; this adds modest evidence of limited ongoing maintenance.
The repository name does not match the package name and its README does not mention this package, so the linkage is not transparent and the package may be piggy-backing on another project's repository.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
php-tmdb/api Version ^4.0 | — | — |
symfony/yaml Version ^5.4 || ^6.0 | — | — |
symfony/config Version ^5.4 || ^6.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.