The package has a clear MIT license, tests, examples, and release notes for this version. Its small dependency set and matching organization-backed repository add transparency, but there is no security policy and the project provides no recent maintenance evidence.
12%
Total Score
50
100
50
75
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.
The package has 19 releases since 2018, but none in the last 12 months; the latest release was about 4 years ago. This strongly supports the abandonment concern.
The repository recorded no commits and no active maintainers in the last 3 months. Together with the archived state, this indicates no current maintenance capacity.
The linked repository is archived and was last pushed about 4 years ago, indicating the project is no longer being actively maintained.
Composer is used for the build, but no security scanning tools are present. The missing scanning is a hygiene gap, secondary to the project's abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.36|^2.10 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.