The package includes a README, an MIT license file, repository tests, and no install-time scripts. It lacks a security policy, and its tiny project footprint limits confidence in long-term support.
56%
Total Score
50
88
83
The repository is owned by an individual rather than an organization, so continuity depends on a single project owner and has limited visible institutional backing.
The latest release was about 3 years and 8 months ago, with no releases in the last 12 months. The package had five releases over its lifetime, so maintenance appears stalled rather than actively ongoing.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since the last release and indicating stalled maintenance.
The repository uses Composer for builds, which fits the package ecosystem, but it reports no security-scanning tools. This is a modest transparency and maintenance gap for a dependency.
The repository has no security policy. For a small geometry library this is not severe, but it leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mjaschen/phpgeo Version ^4.2 | — | — |
hannesvdvreken/pip Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.