The package has no tests or security policy, with no security scanning in its Composer-based repository. MIT licensing and a small dependency set reduce friction, but the single-maintainer project offers little evidence of ongoing support.
35%
Total Score
50
75
Only two releases were published, and the latest was in March 2017; there have been no releases in roughly nine years. This is strong evidence of abandonment for a package intended as an API client.
The artifact includes a README, which helps consumers, but it has no tests or changelog and the repository also has no tests or changelog. The missing tests are a meaningful maintenance gap for an API client.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, here it weakens confidence that the linked repository clearly represents this release.
The repository has zero stars and zero forks, with only one watcher. Popularity is not decisive by itself, but it provides no supporting evidence of active use or community support.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.