The package is an early-stage library with a very short README and seven runtime dependencies. Its small user-facing footprint and missing security tooling make future maintenance and integration harder.
30%
Total Score
0
50
58
50
Only three releases exist, with none in the last 12 months; the latest release was published over four years ago. This is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release history showing no releases for over four years.
Seven runtime dependencies, including database, pagination, validation, and another Telegram package, create a relatively broad dependency surface for a 0.0.x library.
The repository name does not match the package name, and the collected data does not show the package name in its README. This creates uncertainty about whether the linked repository is the package's actual home.
Composer build tooling is present, but no security-scanning tooling was detected. This is a maintenance and transparency gap for a package with multiple runtime dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
respect/validation Version ^2.2 | — | — |
symfony/var-dumper Version ^5.4 | — | — |
chipslays/telegraph Version ^2.0 | — | — |
illuminate/database Version ^8.78 | — | — |
wamania/php-stemmer Version 2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.