It has a stable release line, modest dependencies, tests, and no install scripts. The repository has no security policy or scanning, and the package-to-repository link is not explicit.
57%
Total Score
75
100
64
83
The manifest declares a proprietary license while the repository license file is identified as OSL-3.0. The repository file provides licensing evidence, but the mismatch creates legal ambiguity for consumers.
The package includes tests and the repository also has tests, which supports basic project maturity. The absent package README is a minor documentation gap for an extension consumers must configure.
The latest registry release was nearly six years ago, with no releases in the last 12 months; this is a substantial maintenance concern despite six total releases.
There were no commits or active maintainers in the three months before collection, indicating currently weak development activity even though the repository was pushed in February 2025.
The repository name does not match the package name, and the README was not found to mention the package. That weakens confidence that the linked source is specifically maintained for this release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
creativestyle/utilities Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.