The package includes a README, tests, a release note for 1.0.2, and no install-time scripts. Its repository has had no commits for about seven years, and the MIT declaration conflicts with the BSD-3-Clause license file; pin this version only if its PHP 7-era behavior is acceptable.
58%
Total Score
0
100
71
75
The package has had no registry release in about seven years, with only three releases overall. This is strong evidence of abandonment risk, although the package may be stable and narrowly scoped.
The repository recorded no commits and no active maintainers in the last three months, consistent with no meaningful source activity for about seven years. This materially raises abandonment risk.
A license file is present, but the manifest declares MIT while the artifact and repository license file were detected as BSD-3-Clause. The mismatch reduces transparency and should be resolved before adoption.
Composer is used for the build, but no security-scanning tool is configured. For this small package the missing scanner is a hygiene gap, not a severe dependency risk.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, but it is partly offset by the package's small scope and straightforward source layout.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.