Clear documentation, tests, release notes, and a matching repository support adoption. The single maintainer and absent security policy leave limited resilience if maintenance stops.
68%
Total Score
50
100
88
75
Only one registry account has publish access. That is a real continuity risk for a user-backed project, because a single publisher provides little redundancy if they become unavailable.
The package has 12 releases since February 2, 2026, but the median interval is about 17 minutes, indicating a concentrated early release burst rather than an established cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is the strongest evidence of slowing or paused maintenance in this assessment.
Composer build tooling is present, but no security-scanning tool is configured. The missing scan is a modest transparency gap, not evidence that the package is unsafe.
The repository has no security policy. For a library handling NNTP connections and authentication, this leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.