The package is licensed, documented, tested, and has no install-time scripts. Its single-user project has no security policy or scanning, increasing long-term maintenance risk.
58%
Total Score
50
100
89
75
The repository is owned by the same individual namespace as the package, providing clear ownership but no organizational backing to offset the thin maintenance base.
The package has had no release for more than 3 years, despite 12 releases overall; this is a meaningful sign of stalled maintenance.
There were zero commits and zero active maintainers in the last 3 months, consistent with a repository that has been inactive since March 2023.
Only one issue is open and there has been no recent issue or pull-request activity; this is consistent with low project activity but does not independently indicate abandonment.
Composer build tooling is present, but the repository reports no security scanning, leaving an avoidable maintenance and review gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opis/closure Version ^3.6 | — | — |
monolog/monolog Version ^2.2 | — | — |
nategood/commando Version ^0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.