The source project remains active enough to have recent repository activity, organization backing, and extensive tests. Its small dependency set and OSL-3.0 license are reassuring, but this registry release is several years old and should be pinned deliberately.
55%
Total Score
75
100
88
83
The latest release was published nearly six years ago, with no releases in the past 12 months; this materially raises staleness and compatibility risk, although the repository was pushed more recently.
There were no commits and no active maintainers in the three months before collection, which signals limited current maintenance; the repository's February 2025 push provides only partial compensation.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.0 | — | — |
mikey179/vfsstream Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.