Simple Huawei Push in PHP
57%
Total Score
caution
Usable with caveats: no release or commit activity since December 2021.
Only one registry maintainer is listed, which limits visible publishing capacity. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader maintainer base.
The package has 9 releases but none in the last 12 months, and its latest release was nearly five years ago. This is strong evidence of inactivity, though the release history shows it reached a stable 1.4.1 version.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, corroborating the long period without releases. The repository is not archived, but there is no recent maintenance activity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a package handling push-service credentials, this leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.5.5|^7.0.1 | — | — |
tightenco/collect Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.