The matching repository, MIT declaration, stable version, and readable documentation support basic transparency. Its user-owned project has limited visible backing and no security policy, which weakens confidence in long-term support.
54%
Total Score
25
78
75
There were no commits and no active maintainers in the last 3 months. Combined with the last release being about four years ago, this points to a meaningful abandonment risk.
The repository is owned by an individual user rather than an organization, and no broader project backing is shown. This makes the limited recent activity more dependent on a small ownership base.
The package has had 6 releases since June 2014, but none in the last 12 months; its latest release was about four years ago. This is a substantial maintenance concern despite the established release history.
The repository has 1 star, 1 fork, and 1 watcher, indicating a very small user base. Popularity is supporting evidence only, but this offers little evidence of broad community support.
Composer is used for builds, which is appropriate for a PHP package, but no security scanning tools were detected. This is a modest repository-hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.