It has a clear MIT license, README, tests, and a matching source repository. The Composer install hook adds a small operational concern, while the missing security policy limits transparency.
56%
Total Score
25
100
71
50
This is the only release, published about 4 years and 8 months ago, with no releases in the last 12 months. That substantially raises abandonment risk.
There were no commits and no active maintainers in the last 3 months. Combined with the single old release, this is strong evidence that maintenance has stopped.
The package runs a post-autoload-dump install-time script, which adds execution surface during installation. No other provided signal shows that this script is unsafe, so the effect is limited.
The package and repository are owned by the same individual account, so there is no organizational backing shown to compensate for the inactive maintenance record.
The repository uses Composer, but no security scanning tools were detected. For a small package this is a modest transparency and maintenance gap, not proof of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.