The README documents installation, and Composer is used for dependency management. No release or commit activity has appeared for nearly three years, while the project has no license, security policy, or security scanning.
43%
Total Score
0
64
75
No declared license, license file, or repository license file was detected. That leaves developers without clear permission to use, modify, or redistribute the package.
The latest release was November 14, 2023, with zero releases in the following 12 months and only 10 releases over roughly six years. This indicates a long period without versioned maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the extended release gap and increasing abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. The build setup is a positive; the missing security checks are a modest transparency gap.
The repository has no security policy, reducing transparency about how vulnerability reports would be handled. This is a supporting concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mikey179/vfsstream Version ^1.6 | — | — |
fig/http-message-util Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.