Dependencies are explicit and installation has no lifecycle scripts. The four-file artifact lacks a README, and the repository could not be found, so maintenance and usage guidance are difficult to verify.
34%
Total Score
100
60
75
The package has had no release in over eight years: its latest release was July 2018, with zero releases in the last 12 months. This is strong evidence of abandonment risk.
The manifest declares a proprietary license, so the release is licensed, but it does not provide an identified open-source license or license file for adopters to verify usage rights.
The published artifact contains only four header files and composer.json, indicating a very small distribution. That may be intentional for this package, but it provides little evidence about documentation or project completeness.
The artifact has no README. Tests and a changelog are not expected in a published package artifact, but missing consumer documentation is a real usability gap for a session-handling library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spomky-labs/jose Version 7.1.* | — | — |
intaglio/nuclio-core Version 1.* | — | — |
intaglio/nuclio-plugin-session Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.