Organization backing, a matching repository, tests, and release notes provide useful evidence that the package was deliberately maintained. The absence of a security policy and automated security scanning leaves transparency limited.
45%
Total Score
50
79
50
The package has had no release since March 2020, despite being more than seven years old, which is a substantial abandonment concern. Its ten-release history shows it was previously published actively, but that does not offset the long current gap.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing that development has effectively stopped. The repository was pushed in July 2022, so this is not merely a short-term pause.
Composer is used as the build tool, but no security scanning tools are configured. For a library handling API access, that is a meaningful security-maintenance gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This weakens transparency but is not by itself evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.