The artifact is minimal and lacks a README; the repository also has no security policy or security-scanning tooling. Its Apache-2.0 license and simple Composer dependency profile are positives, but do not offset the maintenance gap.
38%
Total Score
50
100
71
75
This is the package's only release, published in June 2019, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
There were no commits and no active maintainers during the measured three-month period, consistent with the package's long release gap and materially increasing abandonment risk.
The package has no README, which makes integrating this library harder; the absence of tests and a changelog in the published artifact is normal packaging practice and is not treated as a gap.
Composer is used for builds, but no security-scanning tooling is present. This is a transparency and maintenance weakness, though not severe on its own.
The repository has no security policy, leaving users without documented vulnerability-reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.15 | — | — |
paragraph1/php-fcm Version ~0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.