Risky to adopt: the package has seen no release or commit activity for about four years and five months. It is not deprecated or archived, and it includes tests, a readable source tree, and an MIT declaration, but the inactive solo project offers little evidence of ongoing maintenance.
43%
Total Score
0
67
50
The package has only three releases, with the latest published about four years and five months ago and none in the last 12 months. This is strong evidence of abandonment risk for a workflow engine.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided activity signal compensates for this lack of current maintenance.
The repository has zero stars and forks and only one watcher, offering little supporting evidence of an active user or contributor community. Popularity is secondary, but it provides no counterweight to the maintenance gap.
Composer build tooling is present, but no security scanning tools are configured. That leaves fewer visible safeguards for ongoing maintenance, although the absence of workflows means there is no workflow-specific risk to weigh.
No security policy is present, reducing transparency for reporting vulnerabilities in a package that processes workflow definitions. This is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/expression-language Version ~3.4|~4.0|~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.