The small dependency set and absence of install-time scripts reduce operational risk. It also ships without a README, tests, or a license, limiting transparency and safe integration, and those positives do not offset the long abandonment gap.
28%
Total Score
50
100
71
100
No declared license, license file, or repository license file was detected. This creates a material adoption and redistribution concern for an open-source dependency.
The package has no README, tests, or changelog, and the repository also reports no tests or changelog. A GitHub release exists for this version, but it has no release notes to compensate for the missing documentation.
The package has had no release in more than six years: its latest release was January 31, 2020, with zero releases in the last 12 months. Four releases arrived almost together, showing little ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's prolonged release inactivity. The last recorded push was in February 2020.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tooling is present. This is a secondary transparency and maintenance gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
myclabs/php-enum Version ^1.7 | — | — |
ferrumfist/vipip_sdk Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.