The package includes clear setup documentation, release notes, and a matching Apache-2.0 license. Keep ownership and update continuity in mind for a critical production dependency.
68%
Total Score
50
100
86
50
The package and repository are owned by the same individual account rather than an organization. That is consistent ownership, but it offers less visible handoff capacity than organizational backing.
The package has seven releases over about 33 months, but none in the last 12 months; the latest registry release was about 14 months before collection. This indicates a slowing release cadence, though the repository was recently updated.
One contributor made all commits in the last three months, concentrating maintenance responsibility in a single person. The matching personal repository owner provides continuity but does not reduce the succession risk.
Only one commit was recorded in the last three months, so there is recent activity but little demonstrated maintenance throughput. This partly offsets the long gap in registry releases.
The repository uses Composer for builds, but no security scanning tools were detected. The missing scanning is a maintenance hygiene gap, not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0|^3.0 | — | — |
psr/container Version ^2.0 | — | — |
buexplain/netsvr-protocol-php Version ^5.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.