The package is licensed and documented, and its repository contains tests. Its release and commit activity stopped nearly three years ago, while the repository has no security policy, making future maintenance uncertain.
42%
Total Score
50
79
50
The package has 28 releases, but all activity ended on December 3, 2023, with no releases in the last 12 months. That long gap materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly three-year-old last push. This is strong evidence of inactive maintenance.
Composer is used for the build, but no security scanning tool is present. This is a modest supply-chain hygiene gap that adds to the maintenance concerns.
The repository has no security policy. That is a transparency and maintenance gap for a framework package, although it is not evidence of malicious behavior.
The assessed release is v1.0.0, while the registry reports v0.16.3 as the latest version and no recent prerelease activity. This makes the release history and version state harder to interpret.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
event-engine/php-data Version ^1.0 || ^2.0.1 | — | — |
event-engine/php-logger Version ^0.1 || ^0.2.2 | — | — |
event-engine/php-schema Version ^0.1 || ^0.2 || ^0.3 | — | — |
event-engine/php-messaging Version ^0.1 || ^0.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.