The package has substantial recent source activity and readme, tests, changelog, and read-only workflow permissions. Its registry release history is stale, ownership is concentrated, and the package license declaration conflicts with the detected license.
60%
Total Score
75
50
50
50
The release declares 47 runtime dependencies, including many framework modules and development-oriented packages, increasing upgrade and supply-chain complexity for consumers.
The artifact includes license files and the repository has one, but the manifest declares proprietary licensing while the detected license is Apache-2.0. That mismatch needs clarification before adoption.
Only two releases exist, with none in the last 12 months and the latest registry release 932 days after the first; this is a meaningful adoption and maintenance concern, despite recent repository commits.
Two contributors are active, but one contributes about 98% of recent commits. The project is user-owned rather than organization-owned, so this concentration remains a maintenance risk.
The repository name does not match the package name and its README does not mention the package, so the package-to-source relationship is not clearly demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/intl Version ^5.2 | — | — |
phpunit/phpunit Version ^9.5.6 | — | — |
mrclay/jsmin-php Version ^2.4 | — | — |
rinvex/countries Version ^8.1 | — | — |
weline/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.