Documentation, tests in the repository, release notes, and a clear license support adoption. The small project lacks security scanning and a security policy, so pin this version and monitor for renewed maintenance.
62%
Total Score
75
100
88
83
The package has three releases over roughly one week, including the assessed release, showing initial delivery activity but limited history for judging long-term maintenance.
There were zero commits and zero active maintainers in the measured three-month period, a meaningful maintenance and abandonment concern for a package released only recently.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security coverage limited.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
No GitHub Actions workflows were present, so the audit found no workflow hazards; this also means there is no repository automation evidence to support build or security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.