The MIT license, focused README, and matching organization-owned repository make adoption straightforward. A single published maintainer, no security policy, and no security scanning leave limited evidence of ongoing support.
53%
Total Score
50
50
79
75
There were no commits and no active maintainers in the last three months, while the last repository push was in December 2023. This strongly raises abandonment risk.
Seven runtime requirements, including PHP FFI and several FFI-related packages, create a relatively specialized integration surface. The profile is understandable for native-library bindings but may make adoption and maintenance more fragile.
The package has four releases, but its latest release was in December 2023 and it had no releases in the last 12 months. That is meaningful evidence of slowed maintenance.
Composer is used as a build tool, which is appropriate for the package. However, no security scanning tools were detected, leaving a modest repository-hygiene gap.
The repository has no security policy, so there is no documented route for reporting vulnerabilities or describing security handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ffi/proxy Version ^1.0 | — | — |
ffi/location Version ^1.0 | — | — |
ffi/preprocessor Version ^0.2.2 | — | — |
psr/simple-cache Version ^3.0 | — | — |
ffi-headers/contracts Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.