The source is only two files and has no security policy. Install scripts are absent, but that does not offset the limited transparency and maintenance evidence.
34%
Total Score
0
50
67
The package has had only one release, with no releases in over seven years. That is strong evidence of abandonment risk for a dependency, even though a small stable package can sometimes need few releases.
There were no commits and no active maintainers in the last three months, consistent with the repository last being pushed over seven years ago. This materially increases maintenance and abandonment risk.
Neither the package nor the linked repository provides a declared license or license file, leaving users without clear permission to depend on or redistribute the code.
Both the package and repository contain only composer.json and index.php. This may fit a very small utility, but it offers little visible project structure or supporting material.
The artifact has no README, while tests and a changelog are absent as expected packaging gaps; the linked project does have a GitHub release for this version, but provides little consumer guidance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.