The package is clearly identified, licensed, and has a usable README. Its small, single-person project has had no commits or releases for more than four years, so maintenance risk is substantial; pinning this exact version is prudent.
52%
Total Score
25
78
67
The latest release was published more than four years ago, with no releases in the last 12 months. This is strong evidence of stalled maintenance despite a reasonable earlier release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating limited current maintenance capacity.
One registry maintainer is consistent with a small user-owned project, but it leaves little demonstrated redundancy when repository activity is inactive.
The published tree includes multiple private-key files under data/rsa, even though their paths suggest demonstration material. Bundling private-key artifacts raises avoidable transparency and review concerns for a package with cryptography-related code.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these very low counts provide little external validation or visible adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fukuball/jieba-php Version * | — | — |
lustre/php-dfa-sensitive Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.