The MIT license, matching repository, and clear README support adoption. A single maintainer, no security policy, and limited recent development leave modest review and maintenance capacity.
58%
Total Score
50
88
83
Only one registry account can publish the package, which limits publishing redundancy. The linked project is user-owned, so there is no organization backing shown to offset that concentration.
The package has 11 releases but none in the last 12 months, and its latest registry release was in January 2021. This is a substantial maintenance concern despite the package's long history.
The repository recorded no commits and no active maintainers in the last three months. Combined with the old registry release, this points to slow or paused maintenance.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving no documented channel or process for handling vulnerabilities in a package that processes and redirects URLs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^1.1 | — | — |
symfony/cache Version 3.4.47 | — | — |
paragonie/easydb Version ^1 | — | — |
vlucas/phpdotenv Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.