It includes a clear license, tests, documentation, and no install-time scripts. The lack of a security policy and security scanning adds a smaller transparency concern.
15%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement supplied. This is a severe warning that ongoing maintenance and support should not be expected.
The latest release was published in June 2020, and there were no releases in the following 12 months covered by the scan. The package has been available for years but is no longer being released.
The repository had zero commits and zero active maintainers in the last three months. This confirms there is no current maintenance activity to offset the old release history.
The linked source repository is archived, so normal development and issue handling have stopped. Its last push was in March 2022, reinforcing the abandonment risk.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest hygiene gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.