The MIT license, README, tests, and small dependency set make the package straightforward to inspect and adopt. There is no repository security policy or automated security scanning, leaving maintenance safeguards thin.
42%
Total Score
0
100
69
83
The package has had only 3 releases, all around June 2022, and none in the last 12 months despite being roughly 4 years old. This is strong evidence of abandonment risk for a dependency.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has been inactive for years and increasing abandonment risk.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of broad community support.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a modest maintenance and assurance gap.
The linked repository is not archived, which is a positive sign, but its last push was in June 2022 and does not compensate for the broader inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/var-dumper Version ^6.1 | — | — |
stichoza/google-translate-php Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.