It includes tests, a README, a stable MIT release, and no install-time scripts. A single maintainer and no security policy or scanning reduce confidence for long-term use.
56%
Total Score
50
86
75
One registry maintainer is responsible for publishing the package, leaving a thin operational base. The linked repository is owned by the same individual, which provides consistency but not redundancy.
Only two releases exist, with the latest published in August 2023 and none in the last three years, indicating substantially slowed maintenance. The stable version profile provides some maturity but does not offset the inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This raises abandonment risk for a package that may need compatibility updates.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a modest hygiene concern rather than evidence of an unsafe release.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is partly offset by the package's small scope, but remains a transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.