Healthy and reasonable to depend on, with a small maintenance and usability caveat. The repository is active, tested, licensed, and has a security policy, but the package omits a README and recent work is concentrated in two contributors.
78%
Total Score
83
100
88
88
The package runs pre-install and pre-update commands, adding install-time behavior that deserves review before adoption, although this signal alone does not establish that the package is unhealthy.
The artifact has no README, which is a usability gap for a library consumers must integrate, but the repository has both tests and a changelog, showing project-level maintenance and documentation practices.
Only two contributors were active recently, and the leading contributor made about 77% of commits. That concentration creates some continuity risk because the repository is user-owned rather than organization-owned.
Composer build tooling is present, but no security-scanning tool was detected. This is a transparency gap, though other repository controls partially compensate.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
danog/php-rtc-mixin Version ^1.1.6 || ^2.0 | — | — |
danog/php-rtc-exception Version ^1.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.