It has no license, no README, and only two published files, leaving little guidance or legal clarity. Its dependency set is small and it has no install-time scripts, but that does not offset the age and transparency gaps.
30%
Total Score
100
60
75
Only two releases were published, both in April 2018, with no release in more than eight years. That long absence is strong evidence of abandonment risk.
No license is declared, detected, or included in the package, so legal reuse terms are unclear and this materially lowers adoption confidence.
The artifact contains only composer.json and src/PloomesApi.php, providing little visible context for how the library is used or maintained. The small footprint is not inherently unsafe, but it limits transparency.
The library artifact has no README, leaving consumers without published integration guidance; absent tests and changelog are normal for a published artifact and are not treated as gaps.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.