The package has a README, tests, release notes, and an organization-backed repository. However, its source repository has had no commits or active maintainers for three months; use the replacement package zenithgram/zenithgram instead.
18%
Total Score
0
75
50
Packagist marks the entire package as abandoned and names zenithgram/zenithgram as its replacement. This directly indicates that developers should not start new dependencies on this package.
The repository recorded 0 commits and 0 active maintainers during the last three months, which is a strong abandonment warning despite earlier release activity.
The linked repository neither matches the package name nor mentions the package in its README, weakening confidence that it is the intended source for this release.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although it is secondary to the package's abandoned status.
The sole workflow was fully analyzed and uses job-level permissions, with no dangerous triggers or audit findings. All 3 action references are unpinned, leaving a modest reproducibility and workflow-supply-chain gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
amphp/file Version ^3.2 | — | — |
amphp/redis Version ^2.0 | — | — |
psr/container Version ^2.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
amphp/http-client Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.