The package is well documented and tested, with clear licensing and organization ownership. Workflow image pinning and the missing security policy add smaller maintenance concerns.
55%
Total Score
50
78
75
The package has had no registry release in about three years, despite nine releases overall; this is a meaningful abandonment concern for a library dependency.
No commits and no active maintainers were recorded in the last three months, reinforcing the risk that maintenance has stalled.
Although the project released regularly early on, zero releases in the last 12 months indicates the published dependency is no longer actively refreshed.
The repository uses Composer and Make, but no security scanning tool was detected, leaving a modest source-maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ratchet/pawl Version ^0.4.1 | — | — |
symfony/yaml Version ^6.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
vlucas/phpdotenv Version ^5.4 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.