It includes a substantial README, tests, and matching Apache-2.0 licensing. The small, inactive repository and lack of security policy reduce confidence in future fixes.
55%
Total Score
50
100
83
83
There were zero commits and zero active maintainers in the last three months, consistent with no development since March 2021. This materially raises abandonment and future-fix risk.
The repository is owned by an individual user rather than an organization, so there is no organizational backing signal to compensate for the thin maintenance evidence.
The package has 42 releases but none in the last 12 months, and its latest release was about five and a half years ago. This is a meaningful maintenance concern despite the established release history.
The repository has zero stars, forks, and watchers, providing little supporting evidence of external adoption or review. Popularity is supporting evidence only, so this modestly lowers confidence rather than determining the verdict.
The repository uses Composer, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.0|^2.0 | — | — |
google/apiclient Version ~2.0 | — | — |
guzzlehttp/guzzle Version ~6.3 | — | — |
robrichards/xmlseclibs Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.