The stable 1.0.0 release and lack of install-time scripts are modest positives. No release has appeared since April 2020, and the linked repository contains only composer.json with no tests or changelog, leaving little evidence of ongoing maintenance.
38%
Total Score
100
72
50
Both the published artifact and linked repository contain only composer.json. That unusually minimal tree provides little transparency into implementation, testing, or maintenance.
The package has made only one release, on April 17, 2020, with no releases in roughly six years. This is strong evidence of abandonment risk despite the package not being deprecated.
The artifact having no tests, changelog, or README is not inherently concerning for a published PHP artifact, but the repository also reports no tests or changelog, so there is no visible project documentation or validation evidence to compensate for the long inactivity.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no additional maturity signal for this otherwise inactive project.
Composer is used as the build tool, showing basic ecosystem-standard packaging, but no security scanning tools are configured. This is a minor transparency gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.