Integration carries extra maintenance overhead, and security reporting is limited. The package has 43 runtime dependencies, no tests or security policy, and its license metadata differs from the detected license text.
32%
Total Score
0
50
71
75
This is the only release, published about seven years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the repository still being available.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This materially reduces confidence in ongoing maintenance.
The package declares 43 runtime dependencies and no development dependencies, creating substantial transitive maintenance and compatibility burden for a library described as a bundled working snapshot.
A GPL-2.0+ manifest declaration and license files are positive, but the detected artifact license is GPL-2.0, which does not exactly match the declared version range and should be clarified.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. The absence of security scanning tools reinforces this transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0.2 | — | — |
joomla/di Version ^1.5.1 | — | — |
react/dns Version ^0.4.15 | — | — |
slim/slim Version ^3.11 | — | — |
joomla/uri Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.