The MIT license, substantial README, tests, and matching repository make the package transparent to inspect. Its single registry maintainer and missing security policy provide limited resilience and oversight.
38%
Total Score
50
70
75
The latest release was published on December 21, 2016, and there have been no releases in nearly 10 years. Seventeen historical releases show an established package, but not current maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating a strong abandonment risk.
There were no new or closed issues or pull requests in the last month, and no open work remains visible. This reinforces the lack of recent activity, although it is less decisive than the release and commit history.
The repository has no security policy. For a network API client this reduces transparency about vulnerability reporting, though it is secondary to the much older maintenance record.
The assessed version is not a prerelease, but it remains on the 0.1 major line, which provides less compatibility confidence for a package that has not released in nearly 10 years.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.1|~3.0 | — | — |
jms/serializer Version ^1.3 | — | — |
guzzlehttp/guzzle Version ~5.0|~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.