The small artifact has no tests, changelog, README, or repository security scanning, so consumer guidance and maintenance checks are limited. Its single-person ownership and long release interval add uncertainty, although the repository is present, unarchived, and the package is not deprecated.
62%
Total Score
50
71
100
The package declares AGPL-3.0-only, while the artifact license file was detected as GPL-3.0; the presence of license files is positive, but the mismatch creates licensing uncertainty.
The artifact contains no README, tests, or changelog. Missing tests and changelog are normal for a published artifact, while the missing README is a minor usability and transparency gap for a command-line helper.
Only two releases exist since September 2022, with a median interval of about 3 years; the release in the last 12 months is a partial counterweight but does not show a mature cadence.
The repository had no commits and no active maintainers in the last 3 months. Its push date matches the latest release, but there is no evidence of ongoing development afterward.
Composer is used for build and dependency management, which is positive, but the repository reports no security-scanning tools, leaving a modest maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.5.10 | — | — |
vlucas/phpdotenv Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.