The source repository remains linked, unarchived, and clearly matches the package, with a license, README, and tests. However, the registry has not published a release since 2016 and recent repository activity is absent, so pinning this old version carries maintenance risk.
55%
Total Score
50
88
75
One registry account publishes the package. This is consistent with a user-owned project, but it leaves a thin publishing base if that maintainer stops working on it.
The package has 31 releases but none in the last 12 months; its latest registry release was on November 27, 2016, indicating a long period without published maintenance.
There were no commits and no active maintainers in the last 3 months. This supports the concern that the old release is not receiving ongoing maintenance, although the repository is not archived.
Composer is used for the build, but no security-scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a package that interacts with MySQL and accepts application integration, this reduces transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
danielgp/common-lib Version >=1.12.2 | — | — |
danielgp/common-styles Version >=1.0.1 | — | — |
symfony/http-foundation Version >3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.