Usable with caveats: the package is clearly backed by its matching organization repository, has a license, tests, and a solid release history, but recent development has paused and the project lacks security-policy and workflow permission hardening.
68%
Total Score
75
50
83
75
The package has four runtime dependencies, including platform-related packages, so updates and compatibility are not entirely self-contained. The dependency count is still moderate rather than excessive.
The repository recorded zero commits and zero active maintainers during the last three months. This is the clearest maintenance concern, although the January 2026 push and release history provide some counterweight.
The repository has one star, no forks, and no watchers, indicating a very small user and contributor footprint. Popularity is supporting evidence only, so this lowers confidence in external scrutiny rather than making the package unfit.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, partly offset by the repository's basic automated build setup.
No repository security policy was found. This limits transparency about vulnerability reporting and response, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ffi/env Version ^1.0 | — | — |
boson-php/pasm Version ^0.19 | — | — |
boson-php/value-object-contracts Version ^0.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.