The package includes a substantial README, tests, a small runtime dependency set, and no install scripts. Its organization-owned repository is not archived, but the single publisher and absent security policy leave less operational depth.
62%
Total Score
67
100
83
75
Only one account has registry publish access, which is a thin publishing base. The organization-owned repository provides some compensation, so this is a modest concern rather than a severe risk.
The package has 38 releases over nearly seven years, but none in the last 12 months; the latest release was about 15 months ago. This indicates a meaningful maintenance slowdown, though the long release history provides some maturity evidence.
The repository recorded zero commits and zero active maintainers in the last three months. Together with no release in the last year, this lowers confidence that maintenance is currently active.
The repository has five stars, no forks, and one watcher. Popularity is only supporting evidence, but these small numbers provide little evidence of broad review or community support.
Composer is used for builds, but no security scanning tools were detected. The missing scanning layer is a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^5.0 | — | — |
nikic/fast-route Version ^1.3 | — | — |
aivec/response-handler Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.