Its small footprint, clear license, README, and tests make the project easy to inspect. Avoid adding it to new projects; use a currently maintained alternative instead.
12%
Total Score
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe warning that the release should not be adopted as a dependency.
The package has only two releases, both published in March 2018, with no releases in the last eight years. This strongly indicates abandonment.
The linked repository is archived and was last pushed about eight years ago, indicating the source is no longer maintained.
The repository has no security policy, which leaves vulnerability-reporting expectations undocumented; the gap adds transparency risk alongside the project's abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chumper/zipper Version ^1.0 | — | — |
vlucas/phpdotenv Version ^2.4 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
laravel-zero/framework Version 5.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.