Tests, release notes, and a repository license provide useful maintenance and transparency evidence. The main concern is that releases and commits stopped over four years ago, with no security policy or scanning to show ongoing oversight.
55%
Total Score
50
79
75
The package has 14 releases since April 2016, but none in the last four years; the latest release was published in May 2022. This materially raises abandonment risk despite the earlier regular cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no recent development evidence.
The artifact contains a license file and the repository also has one, so licensing is not absent. However, the manifest declares MIT while the detected artifact license is BSD-3-Clause, creating an avoidable licensing inconsistency.
There were no new or closed issues or pull requests in the last month, with one pull request still open. This supports the conclusion that current maintenance activity is limited.
The repository has no security policy, so users have no documented process for reporting or handling security issues. This is a transparency gap, though it does not by itself make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/mink Version ^1.7 | — | — |
behat/behat Version ^3.1.0 | — | — |
nelmio/alice Version ^3.1 | — | — |
fzaninotto/faker Version ^1.6.0 | — | — |
behat/mink-extension Version ^v2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.